Ignore:
Timestamp:
Jun 16, 2009, 5:52:30 PM (16 years ago)
Author:
Herwig Bauernfeind
Message:

Update 3.2 to 3.2.12

Location:
branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample
Files:
11 edited

Legend:

Unmodified
Added
Removed
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/DomApps.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 12. Integrating Additional Services</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="kerberos.html" title="Chapter 11. Active Directory, Kerberos, and Security"><link rel="next" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 12. Integrating Additional Services</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="kerberos.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="HA.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="DomApps"></a>Chapter 12. Integrating Additional Services</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="DomApps.html#id2616162">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616193">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616294">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616327">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616483">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616500">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618352">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618413">Questions and Answers</a></span></dt></dl></div><p>
    2         <a class="indexterm" name="id2616113"></a>
    3         <a class="indexterm" name="id2616119"></a>
    4         <a class="indexterm" name="id2616126"></a>
    5         <a class="indexterm" name="id2616133"></a>
    6         <a class="indexterm" name="id2616140"></a>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 12. Integrating Additional Services</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="kerberos.html" title="Chapter 11. Active Directory, Kerberos, and Security"><link rel="next" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 12. Integrating Additional Services</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="kerberos.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="HA.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="DomApps"></a>Chapter 12. Integrating Additional Services</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="DomApps.html#id2616172">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616202">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616313">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616346">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616502">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616520">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618372">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618432">Questions and Answers</a></span></dt></dl></div><p>
     2        <a class="indexterm" name="id2616122"></a>
     3        <a class="indexterm" name="id2616129"></a>
     4        <a class="indexterm" name="id2616136"></a>
     5        <a class="indexterm" name="id2616142"></a>
     6        <a class="indexterm" name="id2616149"></a>
    77        You've come a long way now. You have pretty much mastered Samba-3 for
    88        most uses it can be put to. Up until now, you have cast Samba-3 in the leading
     
    1515        the latest Windows authentication technologies. Let's get started  this is
    1616        leading edge.
    17         </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616162"></a>Introduction</h2></div></div></div><p>
     17        </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616172"></a>Introduction</h2></div></div></div><p>
    1818        Abmas has continued its miraculous growth; indeed, nothing seems to be able
    1919        to stop its diversification into multiple (and seemingly unrelated) fields.
     
    3131        gradually, taking over key services and easing the way to a full migration and,
    3232        therefore, integration into Abmas's existing business later.
    33         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616193"></a>Assignment Tasks</h3></div></div></div><p>
    34                 <a class="indexterm" name="id2616201"></a>
     33        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616202"></a>Assignment Tasks</h3></div></div></div><p>
    3534                <a class="indexterm" name="id2616210"></a>
     35                <a class="indexterm" name="id2616219"></a>
    3636                You've promised the skeptical Abmas Snack Foods management team
    3737                that you can show them how Samba can ease itself and other Open Source
     
    4040                acquisition). You have chosen Web proxying and caching as your proving ground.
    4141                </p><p>
    42                 <a class="indexterm" name="id2616228"></a>
    43                 <a class="indexterm" name="id2616235"></a>
     42                <a class="indexterm" name="id2616238"></a>
     43                <a class="indexterm" name="id2616245"></a>
    4444                Abmas Snack Foods has several thousand users housed at its head office
    4545                and multiple regional offices, plants, and warehouses. A high proportion of
     
    5151                the earliest commercial users of Microsoft ISA.
    5252                </p><p>
    53                 <a class="indexterm" name="id2616256"></a>
    54                 <a class="indexterm" name="id2616263"></a>
    55                 <a class="indexterm" name="id2616270"></a>
     53                <a class="indexterm" name="id2616275"></a>
     54                <a class="indexterm" name="id2616282"></a>
     55                <a class="indexterm" name="id2616289"></a>
    5656                The team is not happy with ISA. Because it never lived up to its marketing promises,
    5757                it underperformed and had reliability problems. You have pounced on the opportunity
     
    6464                This is a hands-on exercise. You build software applications so
    6565                that you obtain the functionality Abmas needs.
    66                 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616294"></a>Dissection and Discussion</h2></div></div></div><p>
     66                </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616313"></a>Dissection and Discussion</h2></div></div></div><p>
    6767        The key requirements in this business example are straightforward. You are not required
    6868        to do anything new, just to replicate an existing system, not lose any existing features,
     
    7474                </p></li><li><p>
    7575                Seamless and transparent interoperability with the existing Active Directory domain
    76                 </p></li></ul></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616327"></a>Technical Issues</h3></div></div></div><p>
    77                 <a class="indexterm" name="id2616334"></a>
    78                 <a class="indexterm" name="id2616341"></a>
    79                 <a class="indexterm" name="id2616348"></a>
    80                 <a class="indexterm" name="id2616355"></a>
    81                 <a class="indexterm" name="id2616362"></a>
    82                 <a class="indexterm" name="id2616369"></a>
    83                 <a class="indexterm" name="id2616376"></a>
    84                 <a class="indexterm" name="id2616382"></a>
    85                 <a class="indexterm" name="id2616389"></a>
    86                 <a class="indexterm" name="id2616396"></a>
    87                 <a class="indexterm" name="id2616403"></a>
    88                 <a class="indexterm" name="id2616410"></a>
    89                 <a class="indexterm" name="id2616419"></a><a class="indexterm" name="id2616425"></a>
     76                </p></li></ul></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616346"></a>Technical Issues</h3></div></div></div><p>
     77                <a class="indexterm" name="id2616354"></a>
     78                <a class="indexterm" name="id2616361"></a>
     79                <a class="indexterm" name="id2616368"></a>
     80                <a class="indexterm" name="id2616374"></a>
     81                <a class="indexterm" name="id2616381"></a>
     82                <a class="indexterm" name="id2616388"></a>
     83                <a class="indexterm" name="id2616395"></a>
     84                <a class="indexterm" name="id2616402"></a>
     85                <a class="indexterm" name="id2616409"></a>
     86                <a class="indexterm" name="id2616416"></a>
     87                <a class="indexterm" name="id2616423"></a>
     88                <a class="indexterm" name="id2616430"></a>
     89                <a class="indexterm" name="id2616439"></a><a class="indexterm" name="id2616445"></a>
    9090                Functionally, the user's Internet Explorer requests a browsing session with the
    9191                Squid proxy, for which it offers its AD authentication token. Squid hands off
     
    108108                        </p></li><li><p>
    109109                        Tying it all together
    110                         </p></li></ul></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616483"></a>Political Issues</h3></div></div></div><p>
     110                        </p></li></ul></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616502"></a>Political Issues</h3></div></div></div><p>
    111111                You are a stranger in a strange land, and all eyes are upon you. Some would even like to see
    112112                you fail. For you to gain the trust of your newly acquired IT people, it is essential that your
     
    114114                will the entrenched positions consider taking up your new way of doing things on a
    115115                wider scale.
    116                 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616500"></a>Implementation</h2></div></div></div><p>
    117         <a class="indexterm" name="id2616508"></a>
     116                </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2616520"></a>Implementation</h2></div></div></div><p>
     117        <a class="indexterm" name="id2616528"></a>
    118118        First, your system needs to be prepared and in a known good state to proceed. This consists
    119119        of making sure that everything the system depends on is present and that everything that could
     
    122122        they must be removed.
    123123        </p><p>
    124         <a class="indexterm" name="id2616525"></a>
     124        <a class="indexterm" name="id2616545"></a>
    125125        The following packages should be available on your Red Hat Linux system:
    126126        </p><div class="itemizedlist"><ul type="disc"><li><p>
    127                 <a class="indexterm" name="id2616540"></a>
    128                 <a class="indexterm" name="id2616547"></a>
     127                <a class="indexterm" name="id2616560"></a>
     128                <a class="indexterm" name="id2616566"></a>
    129129                krb5-libs
    130130                </p></li><li><p>
     
    137137                pam_krb5
    138138                </p></li></ul></div><p>
    139         <a class="indexterm" name="id2616577"></a>
     139        <a class="indexterm" name="id2616597"></a>
    140140        In the case of SUSE Linux, these packages are called:
    141141        </p><div class="itemizedlist"><ul type="disc"><li><p>
     
    144144                heimdal-devel
    145145                </p></li><li><p>
    146                 <a class="indexterm" name="id2616602"></a>
     146                <a class="indexterm" name="id2616621"></a>
    147147                heimdal
    148148                </p></li><li><p>
     
    153153        for your Linux system to ensure that the packages are correctly updated.
    154154        </p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p>
    155         <a class="indexterm" name="id2616627"></a>
    156         <a class="indexterm" name="id2616634"></a>
    157         <a class="indexterm" name="id2616641"></a>
     155        <a class="indexterm" name="id2616646"></a>
     156        <a class="indexterm" name="id2616653"></a>
     157        <a class="indexterm" name="id2616660"></a>
    158158        If the requirement is for interoperation with MS Windows Server 2003, it
    159159        will be necessary to ensure that you are using MIT Kerberos version 1.3.1
     
    161161        updating.
    162162        </p><p>
    163         <a class="indexterm" name="id2616654"></a>
    164         <a class="indexterm" name="id2616661"></a>
     163        <a class="indexterm" name="id2616674"></a>
     164        <a class="indexterm" name="id2616681"></a>
    165165        Heimdal 0.6 or later is required in the case of SUSE Linux. SUSE Enterprise
    166166        Linux Server 8 ships with Heimdal 0.4. SUSE 9 ships with the necessary version.
    167167        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="ch10-one"></a>Removal of Pre-Existing Conflicting RPMs</h3></div></div></div><p>
    168         <a class="indexterm" name="id2616684"></a>
     168        <a class="indexterm" name="id2616704"></a>
    169169        If Samba and/or Squid RPMs are installed, they should be updated. You can
    170170        build both from source.
    171171        </p><p>
    172         <a class="indexterm" name="id2616696"></a>
    173         <a class="indexterm" name="id2616702"></a>
    174         <a class="indexterm" name="id2616709"></a>
     172        <a class="indexterm" name="id2616716"></a>
     173        <a class="indexterm" name="id2616722"></a>
     174        <a class="indexterm" name="id2616729"></a>
    175175        Locating the packages to be un-installed can be achieved by running:
    176176</p><pre class="screen">
     
    182182<code class="prompt">root# </code> rpm -e samba-common
    183183</pre><p>
    184         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616749"></a>Kerberos Configuration</h3></div></div></div><p>
    185         <a class="indexterm" name="id2616757"></a>
    186         <a class="indexterm" name="id2616764"></a>
    187         <a class="indexterm" name="id2616774"></a>
    188         <a class="indexterm" name="id2616780"></a>
     184        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2616769"></a>Kerberos Configuration</h3></div></div></div><p>
     185        <a class="indexterm" name="id2616777"></a>
     186        <a class="indexterm" name="id2616784"></a>
     187        <a class="indexterm" name="id2616793"></a>
     188        <a class="indexterm" name="id2616800"></a>
    189189        The systems Kerberos installation must be configured to communicate with
    190190        your primary Active Directory server (ADS KDC).
     
    194194        unless you are using Windows 2003 servers.
    195195        </p><p>
    196         <a class="indexterm" name="id2616799"></a>
    197         <a class="indexterm" name="id2616806"></a>
    198         <a class="indexterm" name="id2616813"></a>
    199196        <a class="indexterm" name="id2616819"></a>
    200         <a class="indexterm" name="id2616826"></a>
    201         <a class="indexterm" name="id2616835"></a>
    202         <a class="indexterm" name="id2616842"></a>
     197        <a class="indexterm" name="id2616825"></a>
     198        <a class="indexterm" name="id2616832"></a>
     199        <a class="indexterm" name="id2616839"></a>
     200        <a class="indexterm" name="id2616846"></a>
     201        <a class="indexterm" name="id2616855"></a>
     202        <a class="indexterm" name="id2616861"></a>
    203203        Officially, neither MIT (1.3.4) nor Heimdal (0.63) Kerberos needs an <code class="filename">/etc/krb5.conf</code>
    204204        file in order to work correctly. All ADS domains automatically create SRV records in the
     
    208208        specifying only a single KDC, even if there is more than one. Using the DNS lookup
    209209        allows the KRB5 libraries to use whichever KDCs are available.
    210         </p><div class="procedure"><a name="id2616876"></a><p class="title"><b>Procedure 12.1. Kerberos Configuration Steps</b></p><ol type="1"><li><p>
    211                 <a class="indexterm" name="id2616887"></a>
     210        </p><div class="procedure"><a name="id2616896"></a><p class="title"><b>Procedure 12.1. Kerberos Configuration Steps</b></p><ol type="1"><li><p>
     211                <a class="indexterm" name="id2616907"></a>
    212212                If you find the need to manually configure the <code class="filename">krb5.conf</code>, you should edit it
    213213                to have the contents shown in <a class="link" href="DomApps.html#ch10-krb5conf" title="Example 12.1. Kerberos Configuration File: /etc/krb5.conf">&#8220;Kerberos Configuration  File: /etc/krb5.conf&#8221;</a>. The final fully qualified path for this file
    214214                should be <code class="filename">/etc/krb5.conf</code>.
    215215                </p></li><li><p>
    216                 <a class="indexterm" name="id2616922"></a>
    217                 <a class="indexterm" name="id2616929"></a>
    218                 <a class="indexterm" name="id2616936"></a>
    219                 <a class="indexterm" name="id2616943"></a>
     216                <a class="indexterm" name="id2616942"></a>
    220217                <a class="indexterm" name="id2616949"></a>
    221218                <a class="indexterm" name="id2616956"></a>
    222                 <a class="indexterm" name="id2616963"></a>
    223                 <a class="indexterm" name="id2616970"></a>
    224                 <a class="indexterm" name="id2616977"></a>
    225                 <a class="indexterm" name="id2616986"></a>
    226                 <a class="indexterm" name="id2616993"></a>
    227                 <a class="indexterm" name="id2617000"></a>
     219                <a class="indexterm" name="id2616962"></a>
     220                <a class="indexterm" name="id2616969"></a>
     221                <a class="indexterm" name="id2616976"></a>
     222                <a class="indexterm" name="id2616983"></a>
     223                <a class="indexterm" name="id2616990"></a>
     224                <a class="indexterm" name="id2616997"></a>
    228225                <a class="indexterm" name="id2617006"></a>
     226                <a class="indexterm" name="id2617012"></a>
     227                <a class="indexterm" name="id2617019"></a>
     228                <a class="indexterm" name="id2617026"></a>
    229229                The following gotchas often catch people out. Kerberos is case sensitive. Your realm must
    230230                be in UPPERCASE, or you will get an error: &#8220;<span class="quote">Cannot find KDC for requested realm while getting
     
    242242                when you try to join the realm.
    243243                </p></li><li><p>
    244                 <a class="indexterm" name="id2617051"></a>
     244                <a class="indexterm" name="id2617070"></a>
    245245                You are now ready to test your installation by issuing the command:
    246246</p><pre class="screen">
     
    262262        kdc = w2k3s.london.abmas.biz
    263263        }
    264 </pre></div></div><br class="example-break"><p><a class="indexterm" name="id2617116"></a>
     264</pre></div></div><br class="example-break"><p><a class="indexterm" name="id2617135"></a>
    265265        The command
    266266</p><pre class="screen">
     
    268268</pre><p>
    269269        shows the Kerberos tickets cached by the system.
    270         </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617139"></a>Samba Configuration</h4></div></div></div><p>
    271         <a class="indexterm" name="id2617146"></a>
     270        </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617158"></a>Samba Configuration</h4></div></div></div><p>
     271        <a class="indexterm" name="id2617166"></a>
    272272        Samba must be configured to correctly use Active Directory. Samba-3 must be used, since it
    273273        has the necessary components to interface with Active Directory.
    274         </p><div class="procedure"><a name="id2617157"></a><p class="title"><b>Procedure 12.2. Securing Samba-3 With ADS Support Steps</b></p><ol type="1"><li><p>
    275                 <a class="indexterm" name="id2617169"></a>
    276                 <a class="indexterm" name="id2617176"></a>
    277                 <a class="indexterm" name="id2617183"></a>
    278                 <a class="indexterm" name="id2617190"></a>
    279                 <a class="indexterm" name="id2617196"></a>
     274        </p><div class="procedure"><a name="id2617177"></a><p class="title"><b>Procedure 12.2. Securing Samba-3 With ADS Support Steps</b></p><ol type="1"><li><p>
     275                <a class="indexterm" name="id2617188"></a>
     276                <a class="indexterm" name="id2617195"></a>
     277                <a class="indexterm" name="id2617202"></a>
     278                <a class="indexterm" name="id2617209"></a>
     279                <a class="indexterm" name="id2617216"></a>
    280280                Download the latest stable Samba-3 for Red Hat Linux from the official Samba Team
    281281                <a class="ulink" href="http://ftp.samba.org" target="_top">FTP site.</a> The official Samba Team
     
    283283                needed, and are linked against MIT KRB5 version 1.3.1 and therefore are ready for use.
    284284                </p><p>
    285                 <a class="indexterm" name="id2617223"></a>
    286                 <a class="indexterm" name="id2617230"></a>
     285                <a class="indexterm" name="id2617242"></a>
     286                <a class="indexterm" name="id2617249"></a>
    287287                The necessary, validated RPM packages for SUSE Linux may be obtained from
    288288                the <a class="ulink" href="ftp://ftp.sernet.de/pub/samba" target="_top">SerNet</a> FTP site that
     
    294294                file so it has contents similar to the example shown in <a class="link" href="DomApps.html#ch10-smbconf" title="Example 12.2. Samba Configuration File: /etc/samba/smb.conf">&#8220;Samba Configuration  File: /etc/samba/smb.conf&#8221;</a>.
    295295                </p></li><li><p>
    296                 <a class="indexterm" name="id2617281"></a>
    297                 <a class="indexterm" name="id2617288"></a>
    298                 <a class="indexterm" name="id2617295"></a>i
    299                 <a class="indexterm" name="id2617306"></a>
    300                 <a class="indexterm" name="id2617313"></a>
     296                <a class="indexterm" name="id2617301"></a>
     297                <a class="indexterm" name="id2617307"></a>
     298                <a class="indexterm" name="id2617314"></a>i
     299                <a class="indexterm" name="id2617326"></a>
     300                <a class="indexterm" name="id2617332"></a>
    301301                Next you need to create a computer account in the Active Directory.
    302302                This sets up the trust relationship needed for other clients to
     
    308308</pre><p>
    309309                </p></li><li><p>
    310                 <a class="indexterm" name="id2617347"></a>
    311                 <a class="indexterm" name="id2617354"></a>
    312                 <a class="indexterm" name="id2617361"></a>
    313310                <a class="indexterm" name="id2617367"></a>
    314                 <a class="indexterm" name="id2617374"></a>
     311                <a class="indexterm" name="id2617373"></a>
     312                <a class="indexterm" name="id2617380"></a>
     313                <a class="indexterm" name="id2617387"></a>
     314                <a class="indexterm" name="id2617394"></a>
    315315                Your new Samba binaries must be started in the standard manner as is applicable
    316316                to the platform you are running on. Alternatively, start your Active Directory-enabled Samba with the following commands:
     
    321321</pre><p>
    322322                </p></li><li><p>
    323                 <a class="indexterm" name="id2617415"></a>
    324                 <a class="indexterm" name="id2617422"></a>
    325                 <a class="indexterm" name="id2617431"></a>
    326                 <a class="indexterm" name="id2617438"></a>
    327                 <a class="indexterm" name="id2617445"></a>
     323                <a class="indexterm" name="id2617435"></a>
     324                <a class="indexterm" name="id2617441"></a>
     325                <a class="indexterm" name="id2617451"></a>
     326                <a class="indexterm" name="id2617458"></a>
     327                <a class="indexterm" name="id2617464"></a>
    328328                We now need to test that Samba is communicating with the Active
    329329                Directory domain; most specifically, we want to see whether winbind
     
    358358                This enumerates all the groups in your Active Directory tree.
    359359                </p></li><li><p>
    360                 <a class="indexterm" name="id2617509"></a>
    361                 <a class="indexterm" name="id2617516"></a>
     360                <a class="indexterm" name="id2617528"></a>
     361                <a class="indexterm" name="id2617535"></a>
    362362                Squid uses the <code class="literal">ntlm_auth</code> helper build with Samba-3.
    363363                You may test <code class="literal">ntlm_auth</code> with the command:
     
    371371</pre><p>
    372372                </p></li><li><p>
    373                 <a class="indexterm" name="id2617568"></a>
    374                 <a class="indexterm" name="id2617575"></a>
    375                 <a class="indexterm" name="id2617582"></a>
    376373                <a class="indexterm" name="id2617588"></a>
    377                 <a class="indexterm" name="id2617595"></a>
    378                 <a class="indexterm" name="id2617602"></a>
    379                 <a class="indexterm" name="id2617609"></a>
    380                 <a class="indexterm" name="id2617616"></a>
     374                <a class="indexterm" name="id2617594"></a>
     375                <a class="indexterm" name="id2617601"></a>
     376                <a class="indexterm" name="id2617608"></a>
     377                <a class="indexterm" name="id2617615"></a>
     378                <a class="indexterm" name="id2617622"></a>
     379                <a class="indexterm" name="id2617629"></a>
     380                <a class="indexterm" name="id2617635"></a>
    381381                The <code class="literal">ntlm_auth</code> helper, when run from a command line as the user
    382382                &#8220;<span class="quote">root</span>&#8221;, authenticates against your Active Directory domain (with
     
    396396<code class="prompt">root# </code> chmod 750 /var/lib/samba/winbindd_privileged
    397397</pre><p>
    398                 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617691"></a>NSS Configuration</h4></div></div></div><p>
    399         <a class="indexterm" name="id2617699"></a>
    400         <a class="indexterm" name="id2617705"></a>
    401         <a class="indexterm" name="id2617712"></a>
     398                </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617710"></a>NSS Configuration</h4></div></div></div><p>
     399        <a class="indexterm" name="id2617718"></a>
     400        <a class="indexterm" name="id2617725"></a>
     401        <a class="indexterm" name="id2617732"></a>
    402402        For Squid to benefit from Samba-3, NSS must be updated to allow winbind as a valid route to user authentication.
    403403        </p><p>
    404404        Edit your <code class="filename">/etc/nsswitch.conf</code> file so it has the parameters shown
    405405        in <a class="link" href="DomApps.html#ch10-etcnsscfg" title="Example 12.3. NSS Configuration File Extract File: /etc/nsswitch.conf">&#8220;NSS Configuration File Extract  File: /etc/nsswitch.conf&#8221;</a>.
    406         </p><div class="example"><a name="ch10-smbconf"></a><p class="title"><b>Example 12.2. Samba Configuration  File: <code class="filename">/etc/samba/smb.conf</code></b></p><div class="example-contents"><table class="simplelist" border="0" summary="Simple list"><tr><td> </td></tr><tr><td><em class="parameter"><code>[global]</code></em></td></tr><tr><td><a class="indexterm" name="id2617770"></a><em class="parameter"><code>workgroup = LONDON</code></em></td></tr><tr><td><a class="indexterm" name="id2617782"></a><em class="parameter"><code>netbios name = W2K3S</code></em></td></tr><tr><td><a class="indexterm" name="id2617794"></a><em class="parameter"><code>realm = LONDON.ABMAS.BIZ</code></em></td></tr><tr><td><a class="indexterm" name="id2617806"></a><em class="parameter"><code>security = ads</code></em></td></tr><tr><td><a class="indexterm" name="id2617817"></a><em class="parameter"><code>encrypt passwords = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617829"></a><em class="parameter"><code>password server = w2k3s.london.abmas.biz</code></em></td></tr><tr><td># separate domain and username with '/', like DOMAIN/username</td></tr><tr><td><a class="indexterm" name="id2617846"></a><em class="parameter"><code>winbind separator = /</code></em></td></tr><tr><td># use UIDs from 10000 to 20000 for domain users</td></tr><tr><td><a class="indexterm" name="id2617862"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td># use GIDs from 10000 to 20000 for domain groups</td></tr><tr><td><a class="indexterm" name="id2617877"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr><tr><td># allow enumeration of winbind users and groups</td></tr><tr><td><a class="indexterm" name="id2617893"></a><em class="parameter"><code>winbind enum users = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617905"></a><em class="parameter"><code>winbind enum groups = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617917"></a><em class="parameter"><code>winbind user default domain = yes</code></em></td></tr></table></div></div><br class="example-break"><div class="example"><a name="ch10-etcnsscfg"></a><p class="title"><b>Example 12.3. NSS Configuration File Extract  File: <code class="filename">/etc/nsswitch.conf</code></b></p><div class="example-contents"><pre class="screen">
     406        </p><div class="example"><a name="ch10-smbconf"></a><p class="title"><b>Example 12.2. Samba Configuration  File: <code class="filename">/etc/samba/smb.conf</code></b></p><div class="example-contents"><table class="simplelist" border="0" summary="Simple list"><tr><td> </td></tr><tr><td><em class="parameter"><code>[global]</code></em></td></tr><tr><td><a class="indexterm" name="id2617790"></a><em class="parameter"><code>workgroup = LONDON</code></em></td></tr><tr><td><a class="indexterm" name="id2617802"></a><em class="parameter"><code>netbios name = W2K3S</code></em></td></tr><tr><td><a class="indexterm" name="id2617813"></a><em class="parameter"><code>realm = LONDON.ABMAS.BIZ</code></em></td></tr><tr><td><a class="indexterm" name="id2617825"></a><em class="parameter"><code>security = ads</code></em></td></tr><tr><td><a class="indexterm" name="id2617837"></a><em class="parameter"><code>encrypt passwords = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617849"></a><em class="parameter"><code>password server = w2k3s.london.abmas.biz</code></em></td></tr><tr><td># separate domain and username with '/', like DOMAIN/username</td></tr><tr><td><a class="indexterm" name="id2617865"></a><em class="parameter"><code>winbind separator = /</code></em></td></tr><tr><td># use UIDs from 10000 to 20000 for domain users</td></tr><tr><td><a class="indexterm" name="id2617881"></a><em class="parameter"><code>idmap uid = 10000-20000</code></em></td></tr><tr><td># use GIDs from 10000 to 20000 for domain groups</td></tr><tr><td><a class="indexterm" name="id2617897"></a><em class="parameter"><code>idmap gid = 10000-20000</code></em></td></tr><tr><td># allow enumeration of winbind users and groups</td></tr><tr><td><a class="indexterm" name="id2617913"></a><em class="parameter"><code>winbind enum users = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617925"></a><em class="parameter"><code>winbind enum groups = yes</code></em></td></tr><tr><td><a class="indexterm" name="id2617937"></a><em class="parameter"><code>winbind user default domain = yes</code></em></td></tr></table></div></div><br class="example-break"><div class="example"><a name="ch10-etcnsscfg"></a><p class="title"><b>Example 12.3. NSS Configuration File Extract  File: <code class="filename">/etc/nsswitch.conf</code></b></p><div class="example-contents"><pre class="screen">
    407407passwd: files winbind
    408408shadow: files
    409409group: files winbind
    410 </pre></div></div><br class="example-break"></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617956"></a>Squid Configuration</h4></div></div></div><p>
    411         <a class="indexterm" name="id2617964"></a>
    412         <a class="indexterm" name="id2617971"></a>
     410</pre></div></div><br class="example-break"></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2617976"></a>Squid Configuration</h4></div></div></div><p>
     411        <a class="indexterm" name="id2617983"></a>
     412        <a class="indexterm" name="id2617990"></a>
    413413        Squid must be configured correctly to interact with the Samba-3
    414414        components that handle Active Directory authentication.
    415         </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2617986"></a>Configuration</h3></div></div></div></div><div class="procedure"><a name="id2617991"></a><p class="title"><b>Procedure 12.3. Squid Configuration Steps</b></p><ol type="1"><li><p>
    416                 <a class="indexterm" name="id2618003"></a>
    417                 <a class="indexterm" name="id2618009"></a>
    418                 <a class="indexterm" name="id2618017"></a>
     415        </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2618005"></a>Configuration</h3></div></div></div></div><div class="procedure"><a name="id2618011"></a><p class="title"><b>Procedure 12.3. Squid Configuration Steps</b></p><ol type="1"><li><p>
     416                <a class="indexterm" name="id2618022"></a>
     417                <a class="indexterm" name="id2618029"></a>
     418                <a class="indexterm" name="id2618037"></a>
    419419                If your Linux distribution is SUSE Linux 9, the version of Squid
    420420                supplied is already enabled to use the winbind helper agent. You
     
    422422                programs.
    423423                </p></li><li><p>
    424                 <a class="indexterm" name="id2618034"></a>
    425                 <a class="indexterm" name="id2618041"></a>
    426                 <a class="indexterm" name="id2618048"></a>
    427                 <a class="indexterm" name="id2618055"></a>
    428                 <a class="indexterm" name="id2618062"></a>
     424                <a class="indexterm" name="id2618054"></a>
     425                <a class="indexterm" name="id2618061"></a>
     426                <a class="indexterm" name="id2618068"></a>
     427                <a class="indexterm" name="id2618074"></a>
     428                <a class="indexterm" name="id2618081"></a>
    429429                Squid, by default, runs as the user <code class="constant">nobody</code>. You need to
    430430                add a system user <code class="constant">squid</code> and a system group
     
    434434                and a <code class="constant">squid</code> group in <code class="filename">/etc/group</code> if these aren't there already.
    435435                </p></li><li><p>
    436                 <a class="indexterm" name="id2618109"></a>
    437                 <a class="indexterm" name="id2618116"></a>
     436                <a class="indexterm" name="id2618129"></a>
     437                <a class="indexterm" name="id2618136"></a>
    438438                You now need to change the permissions on Squid's <code class="constant">var</code>
    439439                directory.  Enter the following command:
     
    442442</pre><p>
    443443                </p></li><li><p>
    444                 <a class="indexterm" name="id2618147"></a>
    445                 <a class="indexterm" name="id2618154"></a>
     444                <a class="indexterm" name="id2618167"></a>
     445                <a class="indexterm" name="id2618173"></a>
    446446                Squid must also have control over its logging. Enter the following commands:
    447447</p><pre class="screen">
     
    457457</pre><p>
    458458                </p></li><li><p>
    459                 <a class="indexterm" name="id2618214"></a>
     459                <a class="indexterm" name="id2618233"></a>
    460460                The <code class="filename">/etc/squid/squid.conf</code> file must be edited to include the lines from
    461461                <a class="link" href="DomApps.html#etcsquidcfg" title="Example 12.4. Squid Configuration File Extract /etc/squid.conf [ADMINISTRATIVE PARAMETERS Section]">&#8220;Squid Configuration File Extract  /etc/squid.conf [ADMINISTRATIVE PARAMETERS Section]&#8221;</a> and <a class="link" href="DomApps.html#etcsquid2" title="Example 12.5. Squid Configuration File extract File: /etc/squid.conf [AUTHENTICATION PARAMETERS Section]">&#8220;Squid Configuration File extract  File: /etc/squid.conf [AUTHENTICATION PARAMETERS Section]&#8221;</a>.
    462462                </p></li><li><p>
    463                 <a class="indexterm" name="id2618248"></a>
     463                <a class="indexterm" name="id2618267"></a>
    464464                You must create Squid's cache directories before it may be run.  Enter the following command:
    465465</p><pre class="screen">
     
    488488        acl AuthorizedUsers proxy_auth REQUIRED
    489489        http_access allow all AuthorizedUsers
    490 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2618352"></a>Key Points Learned</h3></div></div></div><p>
    491                 <a class="indexterm" name="id2618360"></a>
    492                 <a class="indexterm" name="id2618367"></a>
    493                 <a class="indexterm" name="id2618374"></a>
    494                 <a class="indexterm" name="id2618381"></a>
    495                 <a class="indexterm" name="id2618393"></a>
     490</pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2618372"></a>Key Points Learned</h3></div></div></div><p>
     491                <a class="indexterm" name="id2618380"></a>
     492                <a class="indexterm" name="id2618387"></a>
     493                <a class="indexterm" name="id2618394"></a>
     494                <a class="indexterm" name="id2618401"></a>
     495                <a class="indexterm" name="id2618412"></a>
    496496                Microsoft Windows networking protocols permeate the spectrum of technologies that Microsoft
    497497                Windows clients use, even when accessing traditional services such as Web browsers. Depending
     
    500500                the cookie-based authentication regime used by all competing browsers. It is Samba's implementation
    501501                of NTLMSSP that makes it attractive to implement the solution that has been demonstrated in this chapter.
    502                 </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2618413"></a>Questions and Answers</h2></div></div></div><p>
    503         <a class="indexterm" name="id2618421"></a>
    504         <a class="indexterm" name="id2618428"></a>
    505         <a class="indexterm" name="id2618435"></a>
    506         <a class="indexterm" name="id2618441"></a>
     502                </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2618432"></a>Questions and Answers</h2></div></div></div><p>
     503        <a class="indexterm" name="id2618440"></a>
     504        <a class="indexterm" name="id2618447"></a>
     505        <a class="indexterm" name="id2618454"></a>
     506        <a class="indexterm" name="id2618461"></a>
    507507        The development of the <code class="literal">ntlm_auth</code> module was first discussed in many Open Source circles
    508508        in 2002. At the SambaXP conference in Goettingen, Germany, Mr. Francesco Chemolli demonstrated the use of
     
    523523        Make certain that your Squid proxy server is equipped with sufficient memory to permit all proxy operations to run
    524524        out of memory without invoking the overheads involved in the use of memory that has to be swapped to disk.
    525         </p><div class="qandaset"><dl><dt> <a href="DomApps.html#id2618519">
     525        </p><div class="qandaset"><dl><dt> <a href="DomApps.html#id2618546">
    526526                What does Samba have to do with Web proxy serving?
    527                 </a></dt><dt> <a href="DomApps.html#id2618685">
     527                </a></dt><dt> <a href="DomApps.html#id2618712">
    528528                What other services does Samba provide?
    529                 </a></dt><dt> <a href="DomApps.html#id2618828">
     529                </a></dt><dt> <a href="DomApps.html#id2618855">
    530530                Does use of Samba (ntlm_auth) improve the performance of Squid?
    531                 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2618519"></a><a name="id2618521"></a></td><td align="left" valign="top"><p>
     531                </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2618546"></a><a name="id2618548"></a></td><td align="left" valign="top"><p>
    532532                What does Samba have to do with Web proxy serving?
    533533                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    534                 <a class="indexterm" name="id2618533"></a>
    535                 <a class="indexterm" name="id2618540"></a>
    536                 <a class="indexterm" name="id2618547"></a>
    537                 <a class="indexterm" name="id2618556"></a>
    538                 <a class="indexterm" name="id2618563"></a>
     534                <a class="indexterm" name="id2618560"></a>
     535                <a class="indexterm" name="id2618567"></a>
     536                <a class="indexterm" name="id2618574"></a>
     537                <a class="indexterm" name="id2618583"></a>
     538                <a class="indexterm" name="id2618590"></a>
    539539                To provide transparent interoperability between Windows clients and the network services
    540540                that are used from them, Samba had to develop tools and facilities that deliver that feature. The benefit
     
    542542                module is basically a wrapper around authentication code from the core of the Samba project.
    543543                </p><p>
    544                 <a class="indexterm" name="id2618585"></a>
    545                 <a class="indexterm" name="id2618592"></a>
    546                 <a class="indexterm" name="id2618601"></a>
    547                 <a class="indexterm" name="id2618610"></a>
     544                <a class="indexterm" name="id2618612"></a>
    548545                <a class="indexterm" name="id2618619"></a>
    549                 <a class="indexterm" name="id2618626"></a>
    550                 <a class="indexterm" name="id2618633"></a>
    551                 <a class="indexterm" name="id2618640"></a>
    552                 <a class="indexterm" name="id2618647"></a>
     546                <a class="indexterm" name="id2618629"></a>
     547                <a class="indexterm" name="id2618638"></a>
     548                <a class="indexterm" name="id2618646"></a>
     549                <a class="indexterm" name="id2618653"></a>
     550                <a class="indexterm" name="id2618660"></a>
     551                <a class="indexterm" name="id2618667"></a>
     552                <a class="indexterm" name="id2618674"></a>
    553553                The <code class="literal">ntlm_auth</code> module supports basic plain-text authentication and NTLMSSP
    554554                protocols. This module makes it possible for Web and FTP proxy requests to be authenticated without
     
    558558                also.
    559559                </p><p>
    560                 <a class="indexterm" name="id2618671"></a>
     560                <a class="indexterm" name="id2618699"></a>
    561561                The short answer is that by adding a wrapper around key authentication components of Samba, other
    562562                projects (like Squid) can benefit from the labors expended in meeting user interoperability needs.
    563                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2618685"></a><a name="id2618687"></a></td><td align="left" valign="top"><p>
     563                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2618712"></a><a name="id2618714"></a></td><td align="left" valign="top"><p>
    564564                What other services does Samba provide?
    565565                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    566                 <a class="indexterm" name="id2618699"></a>
    567                 <a class="indexterm" name="id2618706"></a>
    568                 <a class="indexterm" name="id2618712"></a>
    569                 <a class="indexterm" name="id2618719"></a>
    570566                <a class="indexterm" name="id2618726"></a>
     567                <a class="indexterm" name="id2618733"></a>
     568                <a class="indexterm" name="id2618740"></a>
     569                <a class="indexterm" name="id2618746"></a>
     570                <a class="indexterm" name="id2618753"></a>
    571571                Samba-3 is a file and print server. The core components that provide this functionality are <code class="literal">smbd</code>,
    572572                <code class="literal">nmbd</code>, and the identity resolver daemon, <code class="literal">winbindd</code>.
    573573                </p><p>
    574                 <a class="indexterm" name="id2618757"></a>
    575                 <a class="indexterm" name="id2618763"></a>
     574                <a class="indexterm" name="id2618784"></a>
     575                <a class="indexterm" name="id2618791"></a>
    576576                Samba-3 is an SMB/CIFS client. The core component that provides this is called <code class="literal">smbclient</code>.
    577577                </p><p>
    578                 <a class="indexterm" name="id2618781"></a>
    579                 <a class="indexterm" name="id2618788"></a>
    580                 <a class="indexterm" name="id2618794"></a>
    581                 <a class="indexterm" name="id2618801"></a>
    582578                <a class="indexterm" name="id2618808"></a>
     579                <a class="indexterm" name="id2618815"></a>
     580                <a class="indexterm" name="id2618822"></a>
     581                <a class="indexterm" name="id2618828"></a>
     582                <a class="indexterm" name="id2618835"></a>
    583583                Samba-3 includes a number of helper tools, plug-in modules, utilities, and test and validation facilities.
    584584                Samba-3 includes glue modules that help provide interoperability between MS Windows clients and UNIX/Linux
     
    587587                to permit identity resolution via SMB/CIFS servers (Windows NT4/200x, Samba, and a host of other commercial
    588588                server products).
    589                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2618828"></a><a name="id2618830"></a></td><td align="left" valign="top"><p>
     589                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2618855"></a><a name="id2618858"></a></td><td align="left" valign="top"><p>
    590590                Does use of Samba (<code class="literal">ntlm_auth</code>) improve the performance of Squid?
    591591                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/HA.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 13. Performance, Reliability, and Availability</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="DomApps.html" title="Chapter 12. Integrating Additional Services"><link rel="next" href="ch14.html" title="Chapter 14. Samba Support"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 13. Performance, Reliability, and Availability</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="DomApps.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="ch14.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="HA"></a>Chapter 13. Performance, Reliability, and Availability</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="HA.html#id2618932">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619019">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619520">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2619995">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620323">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620398">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620470">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620570">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620728">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620832">Key Points Learned</a></span></dt></dl></div><p>
    2         <a class="indexterm" name="id2618894"></a>
    3         <a class="indexterm" name="id2618901"></a>
    4         <a class="indexterm" name="id2618907"></a>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 13. Performance, Reliability, and Availability</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="DomApps.html" title="Chapter 12. Integrating Additional Services"><link rel="next" href="ch14.html" title="Chapter 14. Samba Support"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 13. Performance, Reliability, and Availability</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="DomApps.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="ch14.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="HA"></a>Chapter 13. Performance, Reliability, and Availability</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="HA.html#id2618959">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619057">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619557">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620033">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620360">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620435">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620507">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620607">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620755">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620859">Key Points Learned</a></span></dt></dl></div><p>
     2        <a class="indexterm" name="id2618921"></a>
     3        <a class="indexterm" name="id2618928"></a>
     4        <a class="indexterm" name="id2618935"></a>
    55        Well, you have reached one of the last chapters of this book. It is customary to attempt
    66        to wrap up the theme and contents of a book in what is generally regarded as the
     
    1111        </p><div class="blockquote"><table border="0" width="100%" cellspacing="0" cellpadding="0" class="blockquote" summary="Block quote"><tr><td width="10%" valign="top"> </td><td width="80%" valign="top"><p>
    1212        In a world so full of noise, how can the sparrow be heard?
    13         </p></td><td width="10%" valign="top"> </td></tr><tr><td width="10%" valign="top"> </td><td colspan="2" align="right" valign="top">--<span class="attribution">Anonymous</span></td></tr></table></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2618932"></a>Introduction</h2></div></div></div><p>
    14         <a class="indexterm" name="id2618940"></a>
     13        </p></td><td width="10%" valign="top"> </td></tr><tr><td width="10%" valign="top"> </td><td colspan="2" align="right" valign="top">--<span class="attribution">Anonymous</span></td></tr></table></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2618959"></a>Introduction</h2></div></div></div><p>
     14        <a class="indexterm" name="id2618967"></a>
    1515        The sparrow is a small bird whose sounds are drowned out by the noise of the busy
    1616        world it lives in. Likewise, the simple steps that can be taken to improve the
     
    2121        custom tools and methods. Only passing comments are offered concerning these methods.
    2222        </p><p>
    23         <a class="indexterm" name="id2618960"></a>
    24         <a class="indexterm" name="id2618967"></a>
    25         <a class="indexterm" name="id2618974"></a>
     23        <a class="indexterm" name="id2618997"></a>
     24        <a class="indexterm" name="id2619004"></a>
     25        <a class="indexterm" name="id2619011"></a>
    2626<a class="ulink" href="http://www.google.com/search?hl=en&amp;lr=&amp;ie=ISO-8859-1&amp;q=samba+cluster&amp;btnG=Google+Search" target="_top">A search</a>
    2727        for &#8220;<span class="quote">samba cluster</span>&#8221; produced 71,600 hits. And a search for &#8220;<span class="quote">highly available samba</span>&#8221;
     
    3030        availability, reliability, and scalability are of vital interest to corporate network users.
    3131        </p><p>
    32         <a class="indexterm" name="id2619007"></a>
     32        <a class="indexterm" name="id2619044"></a>
    3333        So without further background, you can review a checklist of simple steps that
    3434        can be taken to ensure acceptable network performance while keeping costs of ownership
    3535        well under control.
    36         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619019"></a>Dissection and Discussion</h2></div></div></div><p>
    37         <a class="indexterm" name="id2619027"></a>
    38         <a class="indexterm" name="id2619034"></a>
     36        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619057"></a>Dissection and Discussion</h2></div></div></div><p>
     37        <a class="indexterm" name="id2619065"></a>
     38        <a class="indexterm" name="id2619071"></a>
    3939        If it is your purpose to get the best mileage out of your Samba servers, there is one rule that
    4040        must be obeyed. If you want the best, keep your implementation as simple as possible. You may
     
    4545        complex ones.
    4646        </p><p>
    47         <a class="indexterm" name="id2619056"></a>
    48         <a class="indexterm" name="id2619063"></a>
     47        <a class="indexterm" name="id2619093"></a>
     48        <a class="indexterm" name="id2619100"></a>
    4949        Problems reported by users fall into three categories: configurations that do not work, those
    5050        that have broken behavior, and poor performance. The term <span class="emphasis"><em>broken behavior</em></span>
     
    5555        and at other times not listing them even though the machines are in use on the network.
    5656        </p><p>
    57         <a class="indexterm" name="id2619090"></a>
    58         <a class="indexterm" name="id2619097"></a>
    59         <a class="indexterm" name="id2619104"></a>
    60         <a class="indexterm" name="id2619111"></a>
    61         <a class="indexterm" name="id2619118"></a>
    62         <a class="indexterm" name="id2619124"></a>
     57        <a class="indexterm" name="id2619128"></a>
     58        <a class="indexterm" name="id2619134"></a>
     59        <a class="indexterm" name="id2619141"></a>
     60        <a class="indexterm" name="id2619148"></a>
     61        <a class="indexterm" name="id2619155"></a>
     62        <a class="indexterm" name="id2619162"></a>
    6363        A significant number of reports concern problems with the <code class="literal">smbfs</code> file system
    6464        driver that is part of the Linux kernel, not part of Samba. Users continue to interpret that
     
    7171        Samba and are really foreign to it.
    7272        </p><p>
    73         <a class="indexterm" name="id2619185"></a>
     73        <a class="indexterm" name="id2619222"></a>
    7474        The new project, <code class="literal">cifsfs</code>, is destined to replace <code class="literal">smbfs</code>.
    7575        It, too, is not part of Samba, even though one of the Samba Team members is a prime mover in
     
    7878        Table 13.1 lists typical causes of:
    7979        </p><div class="itemizedlist"><ul type="disc"><li><p>Not Working (NW)</p></li><li><p>Broken Behavior (BB)</p></li><li><p>Poor Performance (PP)</p></li></ul></div><div class="table"><a name="ProbList"></a><p class="title"><b>Table 13.1. Effect of Common Problems</b></p><div class="table-contents"><table summary="Effect of Common Problems" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="center"></colgroup><thead><tr><th align="left"><p>Problem</p></th><th align="center"><p>NW</p></th><th align="center"><p>BB</p></th><th align="center"><p>PP</p></th></tr></thead><tbody><tr><td align="left"><p>File locking</p></td><td align="center"><p>-</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Hardware problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>Incorrect authentication</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Incorrect configuration</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>LDAP problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Name resolution</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>Printing problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr><tr><td align="left"><p>Slow file transfer</p></td><td align="center"><p>-</p></td><td align="center"><p>-</p></td><td align="center"><p>X</p></td></tr><tr><td align="left"><p>Winbind problems</p></td><td align="center"><p>X</p></td><td align="center"><p>X</p></td><td align="center"><p>-</p></td></tr></tbody></table></div></div><br class="table-break"><p>
    80         <a class="indexterm" name="id2619479"></a>
     80        <a class="indexterm" name="id2619516"></a>
    8181        It is obvious to all that the first requirement (as a matter of network hygiene) is to eliminate
    8282        problems that affect basic network operation. This book has provided sufficient working examples
    8383        to help you to avoid all these problems.
    84         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619492"></a>Guidelines for Reliable Samba Operation</h2></div></div></div><p>
    85         <a class="indexterm" name="id2619501"></a>
    86         <a class="indexterm" name="id2619508"></a>
     84        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2619530"></a>Guidelines for Reliable Samba Operation</h2></div></div></div><p>
     85        <a class="indexterm" name="id2619538"></a>
     86        <a class="indexterm" name="id2619545"></a>
    8787        Your objective is to provide a network that works correctly, can grow at all times, is resilient
    8888        at times of extreme demand, and can scale to meet future needs. The following subject areas provide
    8989        pointers that can help you today.
    90         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2619520"></a>Name Resolution</h3></div></div></div><p>
     90        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2619557"></a>Name Resolution</h3></div></div></div><p>
    9191        There are three basic current problem areas: bad hostnames, routed networks, and network collisions.
    9292        These are covered in the following discussion.
    93         </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619531"></a>Bad Hostnames</h4></div></div></div><p>
    94                 <a class="indexterm" name="id2619539"></a>
    95                 <a class="indexterm" name="id2619548"></a>
    96                 <a class="indexterm" name="id2619555"></a>
    97                 <a class="indexterm" name="id2619562"></a>
    98                 <a class="indexterm" name="id2619569"></a>
     93        </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619568"></a>Bad Hostnames</h4></div></div></div><p>
     94                <a class="indexterm" name="id2619576"></a>
     95                <a class="indexterm" name="id2619586"></a>
     96                <a class="indexterm" name="id2619592"></a>
     97                <a class="indexterm" name="id2619599"></a>
     98                <a class="indexterm" name="id2619606"></a>
    9999                When configured as a DHCP client, a number of Linux distributions set the system hostname
    100100                to <code class="constant">localhost</code>. If the parameter <em class="parameter"><code>netbios name</code></em> is not
     
    108108                correctly.
    109109                </p><p>
    110                 <a class="indexterm" name="id2619624"></a>
     110                <a class="indexterm" name="id2619661"></a>
    111111                A few sites have tried to name Windows clients and Samba servers with a name that begins
    112112                with the digits 1-9. This does not work either because it may result in the client or
    113113                server attempting to use that name as an IP address.
    114114                </p><p>
    115                 <a class="indexterm" name="id2619638"></a>
    116                 <a class="indexterm" name="id2619647"></a>
     115                <a class="indexterm" name="id2619675"></a>
     116                <a class="indexterm" name="id2619684"></a>
    117117                A Samba server called <code class="constant">FRED</code> in a NetBIOS domain called <code class="constant">COLLISION</code>
    118118                in a network environment that is part of the fully-qualified Internet domain namespace known
     
    123123                fails given that you probably do not have this in your DNS namespace.
    124124                </p><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p>
    125                 <a class="indexterm" name="id2619691"></a>
    126                 <a class="indexterm" name="id2619700"></a>
    127                 <a class="indexterm" name="id2619707"></a>
     125                <a class="indexterm" name="id2619728"></a>
     126                <a class="indexterm" name="id2619738"></a>
     127                <a class="indexterm" name="id2619744"></a>
    128128                An Active Directory realm called <code class="constant">collision.parrots.com</code> is perfectly okay,
    129129                although it too must be capable of being resolved via DNS, something that functions correctly
    130130                if Windows 200x ADS has been properly installed and configured.
    131                 </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619723"></a>Routed Networks</h4></div></div></div><p>
    132                 <a class="indexterm" name="id2619731"></a>
    133                 <a class="indexterm" name="id2619738"></a>
    134                 <a class="indexterm" name="id2619747"></a>
     131                </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619760"></a>Routed Networks</h4></div></div></div><p>
     132                <a class="indexterm" name="id2619768"></a>
     133                <a class="indexterm" name="id2619775"></a>
     134                <a class="indexterm" name="id2619784"></a>
    135135                NetBIOS networks (Windows networking with NetBIOS over TCP/IP enabled) makes extensive use
    136136                of UDP-based broadcast traffic, as you saw during the exercises in <a class="link" href="primer.html" title="Chapter 16. Networking Primer">&#8220;Networking Primer&#8221;</a>.
    137137                </p><p>
    138                 <a class="indexterm" name="id2619767"></a>
    139                 <a class="indexterm" name="id2619774"></a>
    140                 <a class="indexterm" name="id2619780"></a>
     138                <a class="indexterm" name="id2619804"></a>
     139                <a class="indexterm" name="id2619811"></a>
     140                <a class="indexterm" name="id2619818"></a>
    141141                UDP broadcast traffic is not forwarded by routers. This means that NetBIOS broadcast-based
    142142                networking cannot function across routed networks (i.e., multi-subnet networks) unless
    143143                special provisions are made:
    144144                </p><div class="itemizedlist"><ul type="disc"><li><p>
    145                         <a class="indexterm" name="id2619797"></a>
    146                         <a class="indexterm" name="id2619804"></a>
    147                         <a class="indexterm" name="id2619811"></a>
     145                        <a class="indexterm" name="id2619835"></a>
     146                        <a class="indexterm" name="id2619841"></a>
     147                        <a class="indexterm" name="id2619848"></a>
    148148                        Either install on every Windows client an LMHOSTS file (located in the directory
    149149                        <code class="filename">C:\windows\system32\drivers\etc</code>). It is also necessary to
     
    152152                        manual page for the <code class="filename">smb.conf</code> file.
    153153                        </p></li><li><p>
    154                         <a class="indexterm" name="id2619857"></a>
     154                        <a class="indexterm" name="id2619894"></a>
    155155                        Or configure Samba as a WINS server, and configure all network clients to use that
    156156                        WINS server in their TCP/IP configuration.
    157157                        </p></li></ul></div><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p>
    158                 <a class="indexterm" name="id2619874"></a>
    159                 <a class="indexterm" name="id2619883"></a>
     158                <a class="indexterm" name="id2619911"></a>
     159                <a class="indexterm" name="id2619920"></a>
    160160                The use of DNS is not an acceptable substitute for WINS. DNS does not store specific
    161161                information regarding NetBIOS networking particulars that get stored in the WINS
    162162                name resolution database and that Windows clients require and depend on.
    163                 </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619896"></a>Network Collisions</h4></div></div></div><p>
    164                 <a class="indexterm" name="id2619904"></a>
    165                 <a class="indexterm" name="id2619913"></a>
    166                 <a class="indexterm" name="id2619922"></a>
    167                 <a class="indexterm" name="id2619929"></a>
     163                </p></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2619933"></a>Network Collisions</h4></div></div></div><p>
     164                <a class="indexterm" name="id2619941"></a>
     165                <a class="indexterm" name="id2619950"></a>
     166                <a class="indexterm" name="id2619959"></a>
     167                <a class="indexterm" name="id2619966"></a>
    168168                Excessive network activity causes NetBIOS network timeouts. Timeouts may result in
    169169                blue screen of death (BSOD) experiences. High collision rates may be caused by excessive
     
    174174                in <a class="link" href="primer.html" title="Chapter 16. Networking Primer">&#8220;Networking Primer&#8221;</a>.
    175175                </p><p>
    176                 <a class="indexterm" name="id2619958"></a>
    177                 <a class="indexterm" name="id2619965"></a>
    178                 <a class="indexterm" name="id2619972"></a>
     176                <a class="indexterm" name="id2619995"></a>
     177                <a class="indexterm" name="id2620002"></a>
     178                <a class="indexterm" name="id2620009"></a>
    179179                Under no circumstances should the facility be supported by many routers, known as <code class="constant">NetBIOS
    180180                forwarding</code>, unless you know exactly what you are doing. Inappropriate use of this
     
    184184                less than 15 KB/sec. After the NetBIOS forwarding was turned off, file transfer performance
    185185                immediately returned to 11 MB/sec.
    186                 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2619995"></a>Samba Configuration</h3></div></div></div><p>
     186                </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620033"></a>Samba Configuration</h3></div></div></div><p>
    187187        As a general rule, the contents of the <code class="filename">smb.conf</code> file should be kept as simple as possible.
    188188        No parameter should be specified unless you know it is essential to operation.
    189189        </p><p>
    190         <a class="indexterm" name="id2620015"></a>
    191         <a class="indexterm" name="id2620022"></a>
    192         <a class="indexterm" name="id2620029"></a>
     190        <a class="indexterm" name="id2620052"></a>
     191        <a class="indexterm" name="id2620060"></a>
     192        <a class="indexterm" name="id2620066"></a>
    193193        Many UNIX administrators like to fully document the settings in the <code class="filename">smb.conf</code> file. This is a
    194194        bad idea because it adds content to the file. The <code class="filename">smb.conf</code> file is re-read by every <code class="literal">smbd</code>
     
    198198        It is recommended to keep a fully documented <code class="filename">smb.conf</code> file on hand, and then to operate Samba only
    199199        with an optimized file.
    200         </p><p><a class="indexterm" name="id2620079"></a>
     200        </p><p><a class="indexterm" name="id2620116"></a>
    201201        The preferred way to maintain a documented file is to call it something like <code class="filename">smb.conf.master</code>.
    202202        You can generate the optimized file by executing:
     
    224224Press enter to see a dump of your service definitions
    225225</pre><p>
    226         <a class="indexterm" name="id2620138"></a>
     226        <a class="indexterm" name="id2620176"></a>
    227227        You now, of course, press the enter key to complete the command, or else abort it by pressing Ctrl-C.
    228228        The important thing to note is the noted Server role, as well as warning messages. Noted configuration
     
    234234</pre><p>
    235235        </p><p>
    236         <a class="indexterm" name="id2620166"></a>
    237         <a class="indexterm" name="id2620173"></a>
    238         <a class="indexterm" name="id2620180"></a>
     236        <a class="indexterm" name="id2620203"></a>
     237        <a class="indexterm" name="id2620210"></a>
     238        <a class="indexterm" name="id2620217"></a>
    239239        There are two parameters that can cause severe network performance degradation: <em class="parameter"><code>socket options</code></em>
    240240        and <em class="parameter"><code>socket address</code></em>. The <em class="parameter"><code>socket options</code></em> parameter was often necessary
     
    242242        this parameter being set. Do not use either parameter unless it has been proven necessary to use them.
    243243        </p><p>
    244         <a class="indexterm" name="id2620214"></a>
    245         <a class="indexterm" name="id2620221"></a>
    246         <a class="indexterm" name="id2620228"></a>
    247         <a class="indexterm" name="id2620235"></a>
     244        <a class="indexterm" name="id2620251"></a>
     245        <a class="indexterm" name="id2620258"></a>
     246        <a class="indexterm" name="id2620265"></a>
     247        <a class="indexterm" name="id2620272"></a>
    248248        Another <code class="filename">smb.conf</code> parameter that may cause severe network performance degradation is the
    249249        <em class="parameter"><code>strict sync</code></em> parameter. Do not use this at all. There is no good reason
     
    252252        degrade network performance, so do not set it; if you must, do so with caution.
    253253        </p><p>
    254         <a class="indexterm" name="id2620276"></a>
    255         <a class="indexterm" name="id2620283"></a>
    256         <a class="indexterm" name="id2620290"></a>
    257         <a class="indexterm" name="id2620297"></a>
     254        <a class="indexterm" name="id2620313"></a>
     255        <a class="indexterm" name="id2620320"></a>
     256        <a class="indexterm" name="id2620327"></a>
     257        <a class="indexterm" name="id2620334"></a>
    258258        Finally, many network administrators deliberately disable opportunistic locking support. While this
    259259        does not degrade Samba performance, it significantly degrades Windows client performance because
     
    263263        oplock support for operations that are tolerant of it. See <a class="link" href="appendix.html#ch12dblck" title="Shared Data Integrity">&#8220;Shared Data Integrity&#8221;</a> for more
    264264        information.
    265         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620323"></a>Use and Location of BDCs</h3></div></div></div><p>
    266         <a class="indexterm" name="id2620331"></a>
    267         <a class="indexterm" name="id2620337"></a>
    268         <a class="indexterm" name="id2620344"></a>
    269         <a class="indexterm" name="id2620351"></a>
    270         <a class="indexterm" name="id2620358"></a>
     265        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620360"></a>Use and Location of BDCs</h3></div></div></div><p>
     266        <a class="indexterm" name="id2620368"></a>
     267        <a class="indexterm" name="id2620374"></a>
     268        <a class="indexterm" name="id2620381"></a>
     269        <a class="indexterm" name="id2620388"></a>
     270        <a class="indexterm" name="id2620395"></a>
    271271        On a network segment where there is a PDC and a BDC, the BDC carries the bulk of the network logon
    272272        processing. If the BDC is a heavily loaded server, the PDC carries a greater proportion of
     
    276276        and is undesirable.
    277277        </p><p>
    278         <a class="indexterm" name="id2620376"></a>
    279         <a class="indexterm" name="id2620383"></a>
     278        <a class="indexterm" name="id2620413"></a>
     279        <a class="indexterm" name="id2620420"></a>
    280280        As a general guide, instead of adding domain member servers to a network, you would be better advised
    281281        to add BDCs until there are fewer than 30 Windows clients per BDC. Beyond that ratio, you should add
    282282        domain member servers. This practice ensures that there are always sufficient domain controllers
    283283        to handle logon requests and authentication traffic.
    284         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620398"></a>Use One Consistent Version of MS Windows Client</h3></div></div></div><p>
     284        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620435"></a>Use One Consistent Version of MS Windows Client</h3></div></div></div><p>
    285285        Every network client has its own peculiarities. From a management perspective, it is easier to deal
    286286        with one version of MS Windows that is maintained to a consistent update level than it is to deal
     
    290290        have necessitated special handling from the Samba server end. If you want to remain sane, keep you
    291291        client workstation configurations consistent.
    292         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620420"></a>For Scalability, Use SAN-Based Storage on Samba Servers</h3></div></div></div><p>
    293         <a class="indexterm" name="id2620429"></a>
    294         <a class="indexterm" name="id2620436"></a>
     292        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620457"></a>For Scalability, Use SAN-Based Storage on Samba Servers</h3></div></div></div><p>
     293        <a class="indexterm" name="id2620466"></a>
     294        <a class="indexterm" name="id2620473"></a>
    295295        Many SAN-based storage systems permit more than one server to share a common data store.
    296296        Use of a shared SAN data store means that you do not need to use time- and resource-hungry data
    297297        synchronization techniques.
    298298        </p><p>
    299         <a class="indexterm" name="id2620450"></a>
    300         <a class="indexterm" name="id2620456"></a>
     299        <a class="indexterm" name="id2620487"></a>
     300        <a class="indexterm" name="id2620494"></a>
    301301        The use of a collection of relatively low-cost front-end Samba servers that are coupled to
    302302        a shared backend SAN data store permits load distribution while containing costs below that
    303303        of installing and managing a complex clustering facility.
    304         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620470"></a>Distribute Network Load with MSDFS</h3></div></div></div><p>
    305         <a class="indexterm" name="id2620478"></a>
    306         <a class="indexterm" name="id2620485"></a>
     304        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620507"></a>Distribute Network Load with MSDFS</h3></div></div></div><p>
     305        <a class="indexterm" name="id2620515"></a>
     306        <a class="indexterm" name="id2620522"></a>
    307307        Microsoft DFS (distributed file system) technology has been implemented in Samba. MSDFS permits
    308308        data to be accessed from a single share and yet to actually be distributed across multiple actual
     
    310310        implementation of an MSDFS installation.
    311311        </p><p>
    312         <a class="indexterm" name="id2620503"></a>
    313         <a class="indexterm" name="id2620512"></a>
     312        <a class="indexterm" name="id2620540"></a>
     313        <a class="indexterm" name="id2620550"></a>
    314314        The combination of multiple backend servers together with a front-end server and use of MSDFS
    315315        can achieve almost the same as you would obtain with a clustered Samba server.
    316         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620524"></a>Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</h3></div></div></div><p>
    317         <a class="indexterm" name="id2620533"></a>
    318         <a class="indexterm" name="id2620540"></a>
    319         <a class="indexterm" name="id2620547"></a>
     316        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620562"></a>Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</h3></div></div></div><p>
     317        <a class="indexterm" name="id2620570"></a>
     318        <a class="indexterm" name="id2620577"></a>
     319        <a class="indexterm" name="id2620584"></a>
    320320        Consider using <code class="literal">rsync</code> to replicate data across the WAN during times
    321321        of low utilization. Users can then access the replicated data store rather than needing to do so
     
    324324        implementation if you choose to permit modification and return replication of the modified file;
    325325        otherwise, you may inadvertently overwrite important data.
    326         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620570"></a>Hardware Problems</h3></div></div></div><p>
    327         <a class="indexterm" name="id2620578"></a>
    328         <a class="indexterm" name="id2620585"></a>
    329         <a class="indexterm" name="id2620592"></a>
    330         <a class="indexterm" name="id2620599"></a>
    331         <a class="indexterm" name="id2620608"></a>
    332         <a class="indexterm" name="id2620617"></a>
     326        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620607"></a>Hardware Problems</h3></div></div></div><p>
     327        <a class="indexterm" name="id2620615"></a>
     328        <a class="indexterm" name="id2620622"></a>
     329        <a class="indexterm" name="id2620629"></a>
     330        <a class="indexterm" name="id2620636"></a>
     331        <a class="indexterm" name="id2620645"></a>
     332        <a class="indexterm" name="id2620654"></a>
    333333        Networking hardware prices have fallen sharply over the past 5 years. A surprising number
    334334        of Samba networking problems over this time have been traced to defective network interface
    335335        cards (NICs) or defective HUBs, switches, and cables.
    336336        </p><p>
    337         <a class="indexterm" name="id2620634"></a>
     337        <a class="indexterm" name="id2620671"></a>
    338338        Not surprising is the fact that network administrators do not like to be shown to have made
    339339        a bad decision. Money saved in buying low-cost hardware may result in high costs incurred
    340340        in corrective action.
    341341        </p><p>
    342         <a class="indexterm" name="id2620647"></a>
    343         <a class="indexterm" name="id2620654"></a>
    344         <a class="indexterm" name="id2620661"></a>
    345         <a class="indexterm" name="id2620668"></a>
    346         <a class="indexterm" name="id2620675"></a>
     342        <a class="indexterm" name="id2620684"></a>
     343        <a class="indexterm" name="id2620691"></a>
     344        <a class="indexterm" name="id2620698"></a>
     345        <a class="indexterm" name="id2620705"></a>
     346        <a class="indexterm" name="id2620712"></a>
    347347        Defective NICs, HUBs, and switches may appear as intermittent network access problems, intermittent
    348348        or persistent data corruption, slow network throughput, low performance, or even as BSOD
     
    353353        Defective hardware problems may take patience and persistence before the real cause can be discovered.
    354354        </p><p>
    355         <a class="indexterm" name="id2620698"></a>
     355        <a class="indexterm" name="id2620736"></a>
    356356        Networking hardware defects can significantly impact perceived Samba performance, but defective
    357357        RAID controllers as well as SCSI and IDE hard disk controllers have also been known to impair Samba server
     
    360360        administrator until the entire server was replaced. While you may well think that this would never
    361361        happen to you, experience shows that given the right (unfortunate) circumstances, this can happen to anyone.
    362         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620728"></a>Large Directories</h3></div></div></div><p>
     362        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2620755"></a>Large Directories</h3></div></div></div><p>
    363363        There exist applications that create or manage directories containing many thousands of files. Such
    364364        applications typically generate many small files (less than 100 KB). At the best of times, under UNIX,
     
    400400        as specified in the <code class="filename">smb.conf</code> stanza. This means that smbd will not be able to find lower case
    401401        filenames with these settings.  Note, this is done on a per-share basis.
    402         </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620832"></a>Key Points Learned</h2></div></div></div><p>
     402        </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2620859"></a>Key Points Learned</h2></div></div></div><p>
    403403        This chapter has touched in broad sweeps on a number of simple steps that can be taken
    404404        to ensure that your Samba network is resilient, scalable, and reliable, and that it
     
    409409        her an even break.
    410410        </p><p>
    411         <a class="indexterm" name="id2620853"></a>
     411        <a class="indexterm" name="id2620880"></a>
    412412        Last, but not least, you should not only keep the network design simple, but also be sure it is
    413413        well documented. This book may serve as your pattern for documenting every
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/RefSection.html

    r231 r272  
    44published regarding Samba, or just to gain a more broad understanding of how Samba can
    55play in a Windows networking world.
    6 </p><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615399">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615533">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616162">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616193">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616294">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616327">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616483">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616500">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618352">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618413">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618932">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619019">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619520">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2619995">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620323">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620398">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620470">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620570">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620728">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620832">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621002">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621220">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621928">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622349">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622695">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622707">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622755">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622895">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622954">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623532">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624529">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625009">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625156">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625241">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625407">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625568">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625629">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625745">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625871">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628089">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628204">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A.
     6</p><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615408">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615543">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616172">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616202">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616313">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616346">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616502">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616520">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618372">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618432">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618959">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619057">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619557">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620033">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620360">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620435">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620507">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620607">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620755">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620859">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621028">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621247">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621955">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622376">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622715">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622727">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622776">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622916">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622975">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623561">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624558">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625032">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625180">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625264">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625430">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625592">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625652">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625769">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625894">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628113">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628227">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A.
    77    GNU General Public License version 3
    8   </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id2628870">A.
     8  </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id2628893">A.
    99    Preamble
    10   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629015">A.
     10  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629038">A.
    1111    TERMS AND CONDITIONS
    12   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629019">A.
     12  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629042">A.
    1313    0. Definitions.
    14   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629111">A.
     14  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629134">A.
    1515    1. Source Code.
    16   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629210">A.
     16  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629233">A.
    1717    2. Basic Permissions.
    18   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629249">A.
     18  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629272">A.
    1919    3. Protecting Users&#8217; Legal Rights From Anti-Circumvention Law.
    20   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629290">A.
     20  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629308">A.
    2121    4. Conveying Verbatim Copies.
    22   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629317">A.
     22  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629335">A.
    2323    5. Conveying Modified Source Versions.
    24   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629412">A.
     24  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629431">A.
    2525    6. Conveying Non-Source Forms.
    26   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629602">A.
     26  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629620">A.
    2727     7. Additional Terms.
    28    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629738">A.
     28   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629756">A.
    2929     8. Termination.
    30    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629781">A.
     30   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629800">A.
    3131     9. Acceptance Not Required for Having Copies.
    32    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629801">A.
     32   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629819">A.
    3333     10. Automatic Licensing of Downstream Recipients.
    34    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629853">A.
     34   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629871">A.
    3535    11. Patents.
    36   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629988">A.
     36  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630017">A.
    3737    12. No Surrender of Others&#8217; Freedom.
    38   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630010">A.
     38  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A.
    3939    13. Use with the ???TITLE??? Affero General Public License.
    40   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A.
     40  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630067">A.
    4141    14. Revised Versions of this License.
    42   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630101">A.
     42  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630130">A.
    4343    15. Disclaimer of Warranty.
    44   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630128">A.
     44  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630156">A.
    4545    16. Limitation of Liability.
    46   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630148">A.
     46  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630176">A.
    4747    17. Interpretation of Sections 15 and 16.
    48   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630164">A.
     48  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630193">A.
    4949    END OF TERMS AND CONDITIONS
    50   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630168">A.
     50  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630197">A.
    5151    How to Apply These Terms to Your New Programs
    5252  </a></span></dt></dl></dd></dl></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="nw4migration.html">Prev</a> </td><td width="20%" align="center"> </td><td width="40%" align="right"> <a accesskey="n" href="kerberos.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top">Chapter 10. Migrating NetWare Server to Samba-3 </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> Chapter 11. Active Directory, Kerberos, and Security</td></tr></table></div></body></html>
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/apa.html

    r231 r272  
    11<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Appendix A.  GNU General Public License version 3</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="primer.html" title="Chapter 16. Networking Primer"><link rel="next" href="go01.html" title="Glossary"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Appendix A. 
    22    GNU General Public License version 3
    3   </th></tr><tr><td width="20%" align="left"><a accesskey="p" href="primer.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="go01.html">Next</a></td></tr></table><hr></div><div class="appendix" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="id2628840"></a>Appendix A. 
     3  </th></tr><tr><td width="20%" align="left"><a accesskey="p" href="primer.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="go01.html">Next</a></td></tr></table><hr></div><div class="appendix" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="id2628864"></a>Appendix A. 
    44    <acronym class="acronym">GNU</acronym> General Public License version 3
    5   </h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="bridgehead"><a href="apa.html#id2628870">A.
     5  </h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="bridgehead"><a href="apa.html#id2628893">A.
    66    Preamble
    7   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629015">A.
     7  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629038">A.
    88    TERMS AND CONDITIONS
    9   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629019">A.
     9  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629042">A.
    1010    0. Definitions.
    11   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629111">A.
     11  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629134">A.
    1212    1. Source Code.
    13   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629210">A.
     13  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629233">A.
    1414    2. Basic Permissions.
    15   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629249">A.
     15  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629272">A.
    1616    3. Protecting Users&#8217; Legal Rights From Anti-Circumvention Law.
    17   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629290">A.
     17  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629308">A.
    1818    4. Conveying Verbatim Copies.
    19   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629317">A.
     19  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629335">A.
    2020    5. Conveying Modified Source Versions.
    21   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629412">A.
     21  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629431">A.
    2222    6. Conveying Non-Source Forms.
    23   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629602">A.
     23  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629620">A.
    2424     7. Additional Terms.
    25    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629738">A.
     25   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629756">A.
    2626     8. Termination.
    27    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629781">A.
     27   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629800">A.
    2828     9. Acceptance Not Required for Having Copies.
    29    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629801">A.
     29   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629819">A.
    3030     10. Automatic Licensing of Downstream Recipients.
    31    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629853">A.
     31   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629871">A.
    3232    11. Patents.
    33   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629988">A.
     33  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630017">A.
    3434    12. No Surrender of Others&#8217; Freedom.
    35   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630010">A.
     35  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A.
    3636    13. Use with the ???TITLE??? Affero General Public License.
    37   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A.
     37  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630067">A.
    3838    14. Revised Versions of this License.
    39   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630101">A.
     39  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630130">A.
    4040    15. Disclaimer of Warranty.
    41   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630128">A.
     41  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630156">A.
    4242    16. Limitation of Liability.
    43   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630148">A.
     43  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630176">A.
    4444    17. Interpretation of Sections 15 and 16.
    45   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630164">A.
     45  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630193">A.
    4646    END OF TERMS AND CONDITIONS
    47   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630168">A.
     47  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630197">A.
    4848    How to Apply These Terms to Your New Programs
    4949  </a></span></dt></dl></div><p>
     
    5555    Everyone is permitted to copy and distribute verbatim copies of this license
    5656    document, but changing it is not allowed.
    57   </p><h2><a name="id2628870"></a>
     57  </p><h2><a name="id2628893"></a>
    5858    Preamble
    5959  </h2><p>
     
    119119    The precise terms and conditions for copying, distribution and modification
    120120    follow.
    121   </p><h2><a name="id2629015"></a>
     121  </p><h2><a name="id2629038"></a>
    122122    TERMS AND CONDITIONS
    123   </h2><h2><a name="id2629019"></a>
     123  </h2><h2><a name="id2629042"></a>
    124124    0. Definitions.
    125125  </h2><p>
     
    163163    a list of user commands or options, such as a menu, a prominent item in the
    164164    list meets this criterion.
    165   </p><h2><a name="id2629111"></a>
     165  </p><h2><a name="id2629134"></a>
    166166    1. Source Code.
    167167  </h2><p>
     
    203203  </p><p>
    204204    The Corresponding Source for a work in source code form is that same work.
    205   </p><h2><a name="id2629210"></a>
     205  </p><h2><a name="id2629233"></a>
    206206    2. Basic Permissions.
    207207  </h2><p>
     
    228228    conditions stated below.  Sublicensing is not allowed; section 10 makes it
    229229    unnecessary.
    230   </p><h2><a name="id2629249"></a>
     230  </p><h2><a name="id2629272"></a>
    231231    3. Protecting Users&#8217; Legal Rights From Anti-Circumvention Law.
    232232  </h2><p>
     
    243243    third parties&#8217; legal rights to forbid circumvention of technological
    244244    measures.
    245   </p><h2><a name="id2629290"></a>
     245  </p><h2><a name="id2629308"></a>
    246246    4. Conveying Verbatim Copies.
    247247  </h2><p>
     
    256256    You may charge any price or no price for each copy that you convey, and you
    257257    may offer support or warranty protection for a fee.
    258   </p><h2><a name="id2629317"></a>
     258  </p><h2><a name="id2629335"></a>
    259259    5. Conveying Modified Source Versions.
    260260  </h2><p>
     
    292292    permit.  Inclusion of a covered work in an aggregate does not cause
    293293    this License to apply to the other parts of the aggregate.
    294   </p><h2><a name="id2629412"></a>
     294  </p><h2><a name="id2629431"></a>
    295295    6. Conveying Non-Source Forms.
    296296  </h2><p>
     
    387387    and must require no special password or key for unpacking, reading or
    388388    copying.
    389   </p><h2><a name="id2629602"></a>
     389  </p><h2><a name="id2629620"></a>
    390390     7. Additional Terms.
    391391   </h2><p>
     
    451451     of a separately written license, or stated as exceptions; the above
    452452     requirements apply either way.
    453    </p><h2><a name="id2629738"></a>
     453   </p><h2><a name="id2629756"></a>
    454454     8. Termination.
    455455   </h2><p>
     
    477477     reinstated, you do not qualify to receive new licenses for the same
    478478     material under section 10.
    479    </p><h2><a name="id2629781"></a>
     479   </p><h2><a name="id2629800"></a>
    480480     9. Acceptance Not Required for Having Copies.
    481481   </h2><p>
     
    488488     Therefore, by modifying or propagating a covered work, you indicate your
    489489     acceptance of this License to do so.
    490    </p><h2><a name="id2629801"></a>
     490   </p><h2><a name="id2629819"></a>
    491491     10. Automatic Licensing of Downstream Recipients.
    492492   </h2><p>
     
    513513     by making, using, selling, offering for sale, or importing the Program or
    514514     any portion of it.
    515    </p><h2><a name="id2629853"></a>
     515   </p><h2><a name="id2629871"></a>
    516516    11. Patents.
    517517  </h2><p>
     
    580580    implied license or other defenses to infringement that may otherwise be
    581581    available to you under applicable patent law.
    582   </p><h2><a name="id2629988"></a>
     582  </p><h2><a name="id2630017"></a>
    583583    12. No Surrender of Others&#8217; Freedom.
    584584  </h2><p>
     
    592592    Program, the only way you could satisfy both those terms and this License
    593593    would be to refrain entirely from conveying the Program.
    594   </p><h2><a name="id2630010"></a>
     594  </p><h2><a name="id2630039"></a>
    595595    13. Use with the <acronym class="acronym">GNU</acronym> Affero General Public License.
    596596  </h2><p>
     
    603603    section 13, concerning interaction through a network will apply to the
    604604    combination as such.
    605   </p><h2><a name="id2630039"></a>
     605  </p><h2><a name="id2630067"></a>
    606606    14. Revised Versions of this License.
    607607  </h2><p>
     
    628628    However, no additional obligations are imposed on any author or copyright
    629629    holder as a result of your choosing to follow a later version.
    630   </p><h2><a name="id2630101"></a>
     630  </p><h2><a name="id2630130"></a>
    631631    15. Disclaimer of Warranty.
    632632  </h2><p>
     
    639639    YOU.  SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL
    640640    NECESSARY SERVICING, REPAIR OR CORRECTION.
    641   </p><h2><a name="id2630128"></a>
     641  </p><h2><a name="id2630156"></a>
    642642    16. Limitation of Liability.
    643643  </h2><p>
     
    651651    EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
    652652    SUCH DAMAGES.
    653   </p><h2><a name="id2630148"></a>
     653  </p><h2><a name="id2630176"></a>
    654654    17. Interpretation of Sections 15 and 16.
    655655  </h2><p>
     
    660660    warranty or assumption of liability accompanies a copy of the Program in
    661661    return for a fee.
    662   </p><h2><a name="id2630164"></a>
     662  </p><h2><a name="id2630193"></a>
    663663    END OF TERMS AND CONDITIONS
    664   </h2><h2><a name="id2630168"></a>
     664  </h2><h2><a name="id2630197"></a>
    665665    How to Apply These Terms to Your New Programs
    666666  </h2><p>
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/appendix.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 15. A Collection of Useful Tidbits</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="ch14.html" title="Chapter 14. Samba Support"><link rel="next" href="primer.html" title="Chapter 16. Networking Primer"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 15. A Collection of Useful Tidbits</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="ch14.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="primer.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="appendix"></a>Chapter 15. A Collection of Useful Tidbits</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621928">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622349">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622695">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622707">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622755">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622895">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622954">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623532">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624529">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625009">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625156">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625241">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></div><p>
    2         <a class="indexterm" name="id2621349"></a>
    3         <a class="indexterm" name="id2621355"></a>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 15. A Collection of Useful Tidbits</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="ch14.html" title="Chapter 14. Samba Support"><link rel="next" href="primer.html" title="Chapter 16. Networking Primer"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 15. A Collection of Useful Tidbits</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="ch14.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="primer.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="appendix"></a>Chapter 15. A Collection of Useful Tidbits</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621955">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622376">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622715">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622727">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622776">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622916">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622975">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623561">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624558">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625032">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625180">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625264">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></div><p>
     2        <a class="indexterm" name="id2621376"></a>
     3        <a class="indexterm" name="id2621382"></a>
    44        Information presented here is considered to be either basic or well-known material that is informative
    55        yet helpful. Over the years, I have observed an interesting behavior. There is an expectation that
     
    88        as shown in the example given below.
    99        </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="domjoin"></a>Joining a Domain: Windows 200x/XP Professional</h2></div></div></div><p>
    10         <a class="indexterm" name="id2621386"></a>
     10        <a class="indexterm" name="id2621412"></a>
    1111        Microsoft Windows NT/200x/XP Professional platforms can participate in Domain Security.
    1212        This section steps through the process for making a Windows 200x/XP Professional machine a
    1313        member of a Domain Security environment. It should be noted that this process is identical
    1414        when joining a domain that is controlled by Windows NT4/200x as well as a Samba PDC.
    15         </p><div class="procedure"><a name="id2621400"></a><p class="title"><b>Procedure 15.1. Steps to Join a Domain</b></p><ol type="1"><li><p>
     15        </p><div class="procedure"><a name="id2621426"></a><p class="title"><b>Procedure 15.1. Steps to Join a Domain</b></p><ol type="1"><li><p>
    1616                Click <span class="guimenu">Start</span>.
    1717                </p></li><li><p>
     
    5151                Joining the domain is now complete.
    5252                </p></li></ol></div><p>
    53         <a class="indexterm" name="id2621818"></a>
    54         <a class="indexterm" name="id2621825"></a>
     53        <a class="indexterm" name="id2621845"></a>
     54        <a class="indexterm" name="id2621852"></a>
    5555        The screen capture shown in <a class="link" href="appendix.html#swxpp007" title="Figure 15.4. The Computer Name Changes Panel Domain MIDEARTH">&#8220;The Computer Name Changes Panel  Domain MIDEARTH&#8221;</a> has a button labeled <span class="guimenu">More...</span>. This button opens a
    5656        panel in which you can set (or change) the Primary DNS suffix of the computer. This is a parameter that mainly affects members
    5757        of Microsoft Active Directory. Active Directory is heavily oriented around the DNS namespace.
    5858        </p><p>
    59         <a class="indexterm" name="id2621851"></a>
    60         <a class="indexterm" name="id2621858"></a>
     59        <a class="indexterm" name="id2621878"></a>
     60        <a class="indexterm" name="id2621885"></a>
    6161        Where NetBIOS technology uses WINS as well as UDP broadcast as key mechanisms for name resolution, Active Directory servers
    6262        register their services with the Microsoft Dynamic DNS server. Windows clients must be able to query the correct DNS server
    6363        to find the services (like which machines are domain controllers or which machines have the Netlogon service running).
    6464        </p><p>
    65         <a class="indexterm" name="id2621876"></a>
     65        <a class="indexterm" name="id2621903"></a>
    6666        The default setting of the Primary DNS suffix is the Active Directory domain name. When you change the Primary DNS suffix,
    6767        this does not affect domain membership, but it can break network browsing and the ability to resolve your computer name to
     
    7171        Where the client is a member of a Samba domain, it is preferable to leave this field blank.
    7272        </p><p>
    73         <a class="indexterm" name="id2621900"></a>
     73        <a class="indexterm" name="id2621927"></a>
    7474        According to Microsoft documentation, &#8220;<span class="quote">If this computer belongs to a group with <code class="constant">Group Policy</code>
    7575        enabled on <code class="literal">Primary DNS suffice of this computer</code>, the string specified in the Group Policy is used
    7676        as the primary DNS suffix and you might need to restart your computer to view the correct setting. The local setting is
    7777        used only if Group Policy is disabled or unspecified.</span>&#8221;
    78         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621928"></a>Samba System File Location</h2></div></div></div><p><a class="indexterm" name="id2621935"></a><a class="indexterm" name="id2621943"></a><a class="indexterm" name="id2621951"></a>
     78        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621955"></a>Samba System File Location</h2></div></div></div><p><a class="indexterm" name="id2621962"></a><a class="indexterm" name="id2621970"></a><a class="indexterm" name="id2621978"></a>
    7979        One of the frustrations expressed by subscribers to the Samba mailing lists revolves around the choice of where the default Samba Team
    8080        build and installation process locates its Samba files. The location, chosen in the early 1990s, for the default installation is
     
    8484        Several UNIX vendors, and Linux vendors in particular, elected to locate the Samba files in a location other than the Samba Team
    8585        default.
    86         </p><p><a class="indexterm" name="id2621987"></a><a class="indexterm" name="id2621999"></a><a class="indexterm" name="id2622006"></a><a class="indexterm" name="id2622018"></a><a class="indexterm" name="id2622026"></a><a class="indexterm" name="id2622037"></a><a class="indexterm" name="id2622045"></a><a class="indexterm" name="id2622053"></a><a class="indexterm" name="id2622061"></a><a class="indexterm" name="id2622069"></a><a class="indexterm" name="id2622076"></a><a class="indexterm" name="id2622084"></a><a class="indexterm" name="id2622092"></a><a class="indexterm" name="id2622100"></a><a class="indexterm" name="id2622108"></a><a class="indexterm" name="id2622116"></a>
     86        </p><p><a class="indexterm" name="id2622014"></a><a class="indexterm" name="id2622025"></a><a class="indexterm" name="id2622033"></a><a class="indexterm" name="id2622045"></a><a class="indexterm" name="id2622052"></a><a class="indexterm" name="id2622064"></a><a class="indexterm" name="id2622072"></a><a class="indexterm" name="id2622080"></a><a class="indexterm" name="id2622088"></a><a class="indexterm" name="id2622095"></a><a class="indexterm" name="id2622103"></a><a class="indexterm" name="id2622111"></a><a class="indexterm" name="id2622119"></a><a class="indexterm" name="id2622127"></a><a class="indexterm" name="id2622135"></a><a class="indexterm" name="id2622143"></a>
    8787        Linux vendors, working in conjunction with the Free Standards Group (FSG), Linux Standards Base (LSB), and File Hierarchy       
    8888        System (FHS), have elected to locate the configuration files under the <code class="filename">/etc/samba</code> directory, common binary
     
    9393        <code class="filename">/usr/lib/samba</code> directory tree. The files located there include the dynamically loadable modules for the
    9494        passdb backend as well as for the VFS modules.
    95         </p><p><a class="indexterm" name="id2622185"></a><a class="indexterm" name="id2622193"></a><a class="indexterm" name="id2622201"></a>
     95        </p><p><a class="indexterm" name="id2622212"></a><a class="indexterm" name="id2622220"></a><a class="indexterm" name="id2622228"></a>
    9696        Samba creates runtime control files and generates log files. The runtime control files (tdb and dat files) are stored in
    9797        the <code class="filename">/var/lib/samba</code> directory. Log files are created in <code class="filename">/var/log/samba.</code>
     
    9999        When Samba is built and installed using the default Samba Team process, all files are located under the
    100100        <code class="filename">/usr/local/samba</code> directory tree. This makes it simple to find the files that Samba owns.
    101         </p><p><a class="indexterm" name="id2622240"></a>
     101        </p><p><a class="indexterm" name="id2622267"></a>
    102102        One way to find the Samba files that are installed on your UNIX/Linux system is to search for the location
    103103        of all files called <code class="literal">smbd</code>. Here is an example:
     
    132132        Many people have been caught by installation of Samba using the default Samba Team process when it was already installed
    133133        by the platform vendor's method. If your platform uses RPM format packages, you can check to see if Samba is installed by
    134         executing:<a class="indexterm" name="id2622313"></a>
     134        executing:<a class="indexterm" name="id2622340"></a>
    135135</p><pre class="screen">
    136136<code class="prompt">root# </code> rpm -qa | grep samba
     
    144144samba3-client-3.0.20-1
    145145samba3-cifsmount-3.0.20-1
    146         </pre><p><a class="indexterm" name="id2622336"></a>
     146        </pre><p><a class="indexterm" name="id2622362"></a>
    147147        The package names, of course, vary according to how the vendor, or the binary package builder, prepared them.
    148         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2622349"></a>Starting Samba</h2></div></div></div><p><a class="indexterm" name="id2622356"></a>
     148        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2622376"></a>Starting Samba</h2></div></div></div><p><a class="indexterm" name="id2622382"></a>
    149149        Samba essentially consists of two or three daemons. A daemon is a UNIX application that runs in the background and provides services.
    150150        An example of a service is the Apache Web server for which the daemon is called <code class="literal">httpd</code>. In the case of Samba, there
     
    187187exit 0
    188188</pre></div></div><br class="example-break"><div class="variablelist"><dl><dt><span class="term">nmbd</span></dt><dd><p>
    189                         <a class="indexterm" name="id2622418"></a>
    190                         <a class="indexterm" name="id2622425"></a>
     189                        <a class="indexterm" name="id2622445"></a>
     190                        <a class="indexterm" name="id2622452"></a>
    191191                        This daemon handles all name registration and resolution requests. It is the primary vehicle involved
    192192                        in network browsing. It handles all UDP-based protocols. The <code class="literal">nmbd</code> daemon should
    193193                        be the first command started as part of the Samba startup process.
    194194                        </p></dd><dt><span class="term">smbd</span></dt><dd><p>
    195                         <a class="indexterm" name="id2622455"></a>
    196                         <a class="indexterm" name="id2622462"></a>
     195                        <a class="indexterm" name="id2622482"></a>
     196                        <a class="indexterm" name="id2622488"></a>
    197197                        This daemon handles all TCP/IP-based connection services for file- and print-based operations. It also
    198198                        manages local authentication. It should be started immediately following the startup of <code class="literal">nmbd</code>.
    199199                        </p></dd><dt><span class="term">winbindd</span></dt><dd><p>
    200                         <a class="indexterm" name="id2622490"></a>
    201                         <a class="indexterm" name="id2622497"></a>
     200                        <a class="indexterm" name="id2622517"></a>
     201                        <a class="indexterm" name="id2622524"></a>
    202202                        This daemon should be started when Samba is a member of a Windows NT4 or ADS domain. It is also needed when
    203203                        Samba has trust relationships with another domain. The <code class="literal">winbindd</code> daemon will check the
     
    253253        exit 1
    254254esac
    255 </pre></div></div><br class="example-break"><p><a class="indexterm" name="id2622616"></a>
     255</pre></div></div><br class="example-break"><p><a class="indexterm" name="id2622637"></a>
    256256        SUSE Linux implements individual control over each Samba daemon. A Samba control script that can be conveniently
    257257        executed from the command line is shown in <a class="link" href="appendix.html#ch12SL" title="Example 15.1. A Useful Samba Control Script for SUSE Linux">&#8220;A Useful Samba Control Script for SUSE Linux&#8221;</a>. This can be located in the directory
    258258        <code class="filename">/sbin</code> in a file called <code class="filename">samba</code>. This type of control script should be
    259259        owned by user root and group root, and set so that only root can execute it.
    260         </p><p><a class="indexterm" name="id2622652"></a>
     260        </p><p><a class="indexterm" name="id2622672"></a>
    261261        A sample startup script for a Red Hat Linux system is shown in <a class="link" href="appendix.html#ch12RHscript" title="Example 15.2. A Sample Samba Control Script for Red Hat Linux">&#8220;A Sample Samba Control Script for Red Hat Linux&#8221;</a>.
    262262        This file could be located in the directory <code class="filename">/etc/rc.d</code> and can be called
     
    265265        the Samba source code distribution tarball. The packaging files for each platform include a
    266266        startup control file.
    267         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2622695"></a>DNS Configuration Files</h2></div></div></div><p>
     267        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2622715"></a>DNS Configuration Files</h2></div></div></div><p>
    268268        The following files are common to all DNS server configurations. Rather than repeat them multiple times, they
    269269        are presented here for general reference.
    270         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622707"></a>The Forward Zone File for the Loopback Adaptor</h3></div></div></div><p>
     270        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622727"></a>The Forward Zone File for the Loopback Adaptor</h3></div></div></div><p>
    271271        The forward zone file for the loopback address never changes. An example file is shown
    272272        in <a class="link" href="appendix.html#loopback" title="Example 15.3. DNS Localhost Forward Zone File: /var/lib/named/localhost.zone">&#8220;DNS Localhost Forward Zone File: /var/lib/named/localhost.zone&#8221;</a>. All traffic destined for an IP address that is hosted on a
     
    285285                IN NS           @
    286286                IN A            127.0.0.1
    287 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622755"></a>The Reverse Zone File for the Loopback Adaptor</h3></div></div></div><p>
     287</pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622776"></a>The Reverse Zone File for the Loopback Adaptor</h3></div></div></div><p>
    288288        The reverse zone file for the loopback address as shown in <a class="link" href="appendix.html#dnsloopy" title="Example 15.4. DNS Localhost Reverse Zone File: /var/lib/named/127.0.0.zone">&#8220;DNS Localhost Reverse Zone File: /var/lib/named/127.0.0.zone&#8221;</a>
    289289        is necessary so that references to the address <code class="constant">127.0.0.1</code> can be
     
    345345M.ROOT-SERVERS.NET.      3600000      A     202.12.27.33
    346346; End of File
    347 </pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622895"></a>DNS Root Server Hint File</h3></div></div></div><p>
     347</pre></div></div><br class="example-break"></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622916"></a>DNS Root Server Hint File</h3></div></div></div><p>
    348348        The content of the root hints file as shown in <a class="link" href="appendix.html#roothint" title="Example 15.5. DNS Root Name Server Hint File: /var/lib/named/root.hint">&#8220;DNS Root Name Server Hint File: /var/lib/named/root.hint&#8221;</a>  changes slowly over time.
    349349        Periodically this file should be updated from the source shown. Because
    350350          of its size, this file is located at the end of this chapter.
    351         </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="altldapcfg"></a>Alternative LDAP Database Initialization</h2></div></div></div><p><a class="indexterm" name="id2622926"></a><a class="indexterm" name="id2622937"></a>
     351        </p></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="altldapcfg"></a>Alternative LDAP Database Initialization</h2></div></div></div><p><a class="indexterm" name="id2622947"></a><a class="indexterm" name="id2622958"></a>
    352352        The following procedure may be used as an alternative means of configuring
    353353        the initial LDAP database. Many administrators prefer to have greater control
    354354        over how system files get configured.
    355         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622954"></a>Initialization of the LDAP Database</h3></div></div></div><p><a class="indexterm" name="id2622961"></a><a class="indexterm" name="id2622969"></a><a class="indexterm" name="id2622981"></a>
     355        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2622975"></a>Initialization of the LDAP Database</h3></div></div></div><p><a class="indexterm" name="id2622982"></a><a class="indexterm" name="id2622990"></a><a class="indexterm" name="id2623001"></a>
    356356        The first step to get the LDAP server ready for action is to create the LDIF file from
    357357        which the LDAP database will be preloaded. This is necessary to create the containers
     
    706706displayName: Domain Users
    707707description: Domain Users
    708 </pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2623532"></a>The LDAP Account Manager</h2></div></div></div><p>
    709 <a class="indexterm" name="id2623540"></a>
    710 <a class="indexterm" name="id2623547"></a>
    711 <a class="indexterm" name="id2623556"></a>
    712 <a class="indexterm" name="id2623563"></a>
    713 <a class="indexterm" name="id2623570"></a>
    714 <a class="indexterm" name="id2623576"></a>
    715 <a class="indexterm" name="id2623583"></a>
     708</pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2623561"></a>The LDAP Account Manager</h2></div></div></div><p>
     709<a class="indexterm" name="id2623569"></a>
     710<a class="indexterm" name="id2623575"></a>
     711<a class="indexterm" name="id2623585"></a>
     712<a class="indexterm" name="id2623591"></a>
     713<a class="indexterm" name="id2623598"></a>
     714<a class="indexterm" name="id2623605"></a>
     715<a class="indexterm" name="id2623612"></a>
    716716The LDAP Account Manager (LAM) is an application suite that has been written in PHP.
    717717LAM can be used with any Web server that has PHP4 support. It connects to the LDAP
     
    725725of 2005.
    726726</p><p>
    727 <a class="indexterm" name="id2623615"></a>
    728 <a class="indexterm" name="id2623621"></a>
    729 <a class="indexterm" name="id2623628"></a>
     727<a class="indexterm" name="id2623643"></a>
     728<a class="indexterm" name="id2623650"></a>
     729<a class="indexterm" name="id2623657"></a>
    730730Requirements:
    731731</p><div class="itemizedlist"><ul type="disc"><li><p>A web server that will work with PHP4.</p></li><li><p>PHP4 (available from the <a class="ulink" href="http://www.php.net/" target="_top">PHP</a> home page.)</p></li><li><p>OpenLDAP 2.0 or later.</p></li><li><p>A Web browser that supports CSS.</p></li><li><p>Perl.</p></li><li><p>The gettext package.</p></li><li><p>mcrypt + mhash (optional).</p></li><li><p>It is also a good idea to install SSL support.</p></li></ul></div><p>
    732732LAM is a useful tool that provides a simple Web-based device that can be used to
    733733manage the contents of the LDAP directory to:
    734 <a class="indexterm" name="id2623689"></a>
    735 <a class="indexterm" name="id2623696"></a>
    736 <a class="indexterm" name="id2623703"></a>
     734<a class="indexterm" name="id2623717"></a>
     735<a class="indexterm" name="id2623724"></a>
     736<a class="indexterm" name="id2623731"></a>
    737737</p><div class="itemizedlist"><ul type="disc"><li><p>Display user/group/host and Domain entries.</p></li><li><p>Manage entries (Add/Delete/Edit).</p></li><li><p>Filter and sort entries.</p></li><li><p>Store and use multiple operating profiles.</p></li><li><p>Edit organizational units (OUs).</p></li><li><p>Upload accounts from a file.</p></li><li><p>Is compatible with Samba-2.2.x and Samba-3.</p></li></ul></div><p>
    738738When correctly configured, LAM allows convenient management of UNIX (Posix) and Samba
    739739user, group, and windows domain member machine accounts.
    740740</p><p>
    741 <a class="indexterm" name="id2623757"></a>
    742 <a class="indexterm" name="id2623764"></a>
    743 <a class="indexterm" name="id2623771"></a>
    744 <a class="indexterm" name="id2623777"></a>
     741<a class="indexterm" name="id2623785"></a>
     742<a class="indexterm" name="id2623792"></a>
     743<a class="indexterm" name="id2623799"></a>
     744<a class="indexterm" name="id2623806"></a>
    745745The default password is &#8220;<span class="quote">lam.</span>&#8221; It is highly recommended that you use only
    746746an SSL connection to your Web server for all remote operations involving LAM. If you
     
    761761        <code class="filename">/srv/www/htdocs</code> directory.
    762762        </p></li><li><p>
    763         <a class="indexterm" name="id2623857"></a>
     763        <a class="indexterm" name="id2623886"></a>
    764764        Set file permissions using the following commands:
    765765</p><pre class="screen">
     
    771771</pre><p>
    772772        </p></li><li><p>
    773         <a class="indexterm" name="id2623910"></a>
     773        <a class="indexterm" name="id2623938"></a>
    774774       Using your favorite editor create the following <code class="filename">config.cfg</code>
    775775       LAM configuration file:
     
    779779<code class="prompt">root# </code> vi config.cfg
    780780</pre><p>
    781         <a class="indexterm" name="id2623951"></a>
    782         <a class="indexterm" name="id2623960"></a>
     781        <a class="indexterm" name="id2623979"></a>
     782        <a class="indexterm" name="id2623988"></a>
    783783        An example file is shown in <a class="link" href="appendix.html#lamcfg" title="Example 15.11. Example LAM Configuration File config.cfg">&#8220;Example LAM Configuration File  config.cfg&#8221;</a>.
    784784        This is the minimum configuration that must be completed. The LAM profile
     
    795795        change the settings to match local site needs.
    796796        </p></li></ol></div><p>
    797         <a class="indexterm" name="id2624019"></a>
     797        <a class="indexterm" name="id2624048"></a>
    798798        An example of a working file is shown here in <a class="link" href="appendix.html#lamconf" title="Example 15.12. LAM Profile Control File lam.conf">&#8220;LAM Profile Control File  lam.conf&#8221;</a>.
    799799        This file has been stripped of comments to keep the size small. The comments
     
    803803        are preferred at your site.
    804804        </p><p>
    805         <a class="indexterm" name="id2624043"></a>
     805        <a class="indexterm" name="id2624071"></a>
    806806        It is important that your LDAP server is running at the time that LAM is
    807807        being configured. This permits you to validate correct operation.
    808808        An example of the LAM login screen is provided in <a class="link" href="appendix.html#lam-login" title="Figure 15.6. The LDAP Account Manager Login Screen">&#8220;The LDAP Account Manager Login Screen&#8221;</a>.
    809809        </p><div class="figure"><a name="lam-login"></a><p class="title"><b>Figure 15.6. The LDAP Account Manager Login Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-login.png" width="270" alt="The LDAP Account Manager Login Screen"></div></div></div><br class="figure-break"><p>
    810         <a class="indexterm" name="id2624105"></a>
     810        <a class="indexterm" name="id2624134"></a>
    811811        The LAM configuration editor has a number of options that must be managed correctly.
    812812        An example of use of the LAM configuration editor is shown in <a class="link" href="appendix.html#lam-config" title="Figure 15.7. The LDAP Account Manager Configuration Screen">&#8220;The LDAP Account Manager Configuration Screen&#8221;</a>.
     
    818818        using LAM to add additional users and groups.
    819819        </p><div class="figure"><a name="lam-config"></a><p class="title"><b>Figure 15.7. The LDAP Account Manager Configuration Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-config.png" width="270" alt="The LDAP Account Manager Configuration Screen"></div></div></div><br class="figure-break"><p>
    820         <a class="indexterm" name="id2624177"></a>
     820        <a class="indexterm" name="id2624205"></a>
    821821        LAM has some nice, but unusual features. For example, one unexpected feature in most application
    822822        screens permits the generation of a PDF file that lists configuration information. This is a well
     
    824824        space.
    825825        </p><p>
    826         <a class="indexterm" name="id2624192"></a>
     826        <a class="indexterm" name="id2624220"></a>
    827827        When you log onto LAM the opening screen drops you right into the user manager as shown in
    828828        <a class="link" href="appendix.html#lam-user" title="Figure 15.8. The LDAP Account Manager User Edit Screen">&#8220;The LDAP Account Manager User Edit Screen&#8221;</a>. This is a logical action as it permits the most-needed facility
     
    838838        memberships.
    839839        </p><div class="figure"><a name="lam-group"></a><p class="title"><b>Figure 15.9. The LDAP Account Manager Group Edit Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-groups.png" width="270" alt="The LDAP Account Manager Group Edit Screen"></div></div></div><br class="figure-break"><div class="figure"><a name="lam-group-mem"></a><p class="title"><b>Figure 15.10. The LDAP Account Manager Group Membership Edit Screen</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/lam-group-members.png" width="270" alt="The LDAP Account Manager Group Membership Edit Screen"></div></div></div><br class="figure-break"><p>
    840         <a class="indexterm" name="id2624372"></a><a class="indexterm" name="id2624377"></a>
     840        <a class="indexterm" name="id2624400"></a><a class="indexterm" name="id2624406"></a>
    841841        The final screen presented here is one that you should not normally need to use. Host accounts will
    842842        be automatically managed using the smbldap-tools scripts. This means that the screen <a class="link" href="appendix.html#lam-host" title="Figure 15.11. The LDAP Account Manager Host Edit Screen">&#8220;The LDAP Account Manager Host Edit Screen&#8221;</a>
     
    884884cachetimeout: 5
    885885pwdhash: SSHA
    886 </pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2624529"></a>IDEALX Management Console</h2></div></div></div><p>
     886</pre></div></div><br class="example-break"></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2624558"></a>IDEALX Management Console</h2></div></div></div><p>
    887887        IMC (the IDEALX Mamagement Console) is a tool that can be used as the basis for a comprehensive
    888888        web-based management interface for UNIX and Linux systems.
     
    898898        For further information regarding IMC refer to the web <a class="ulink" href="http://imc.sourceforge.net/" target="_top">site.</a>
    899899        Prebuilt RPM packages are also <a class="ulink" href="http://imc.sourceforge.net/download.html" target="_top">available.</a>
    900         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12-SUIDSGID"></a>Effect of Setting File and Directory SUID/SGID Permissions Explained</h2></div></div></div><a class="indexterm" name="id2624635"></a><a class="indexterm" name="id2624642"></a><p>
     900        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12-SUIDSGID"></a>Effect of Setting File and Directory SUID/SGID Permissions Explained</h2></div></div></div><a class="indexterm" name="id2624663"></a><a class="indexterm" name="id2624670"></a><p>
    901901        The setting of the SUID/SGID bits on the file or directory permissions flag has particular
    902902        consequences. If the file is executable and the SUID bit is set, it executes with the privilege
     
    968968drw-rw-r--    2 bobj     Domain Users  12346 Dec 18 18:11 maryvfile.txt
    969969</pre><p>
    970         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12dblck"></a>Shared Data Integrity</h2></div></div></div><p><a class="indexterm" name="id2624873"></a><a class="indexterm" name="id2624880"></a>
     970        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="ch12dblck"></a>Shared Data Integrity</h2></div></div></div><p><a class="indexterm" name="id2624901"></a><a class="indexterm" name="id2624909"></a>
    971971        The integrity of shared data is often viewed as a particularly emotional issue, especially where
    972972        there are concurrent problems with multiuser data access. Contrary to the assertions of some who have
     
    974974        </p><p>
    975975        The solution to concurrent multiuser data access problems must consider three separate areas
    976         from which the problem may stem:<a class="indexterm" name="id2624909"></a><a class="indexterm" name="id2624920"></a><a class="indexterm" name="id2624932"></a>
    977         </p><div class="itemizedlist"><ul type="disc"><li><p>application-level locking controls</p></li><li><p>client-side locking controls</p></li><li><p>server-side locking controls</p></li></ul></div><p><a class="indexterm" name="id2624964"></a><a class="indexterm" name="id2624972"></a>
     976        from which the problem may stem:<a class="indexterm" name="id2624932"></a><a class="indexterm" name="id2624943"></a><a class="indexterm" name="id2624955"></a>
     977        </p><div class="itemizedlist"><ul type="disc"><li><p>application-level locking controls</p></li><li><p>client-side locking controls</p></li><li><p>server-side locking controls</p></li></ul></div><p><a class="indexterm" name="id2624987"></a><a class="indexterm" name="id2624995"></a>
    978978        Many database applications use some form of application-level access control. An example of one
    979979        well-known application that uses application-level locking is Microsoft Access. Detailed guidance
    980980        is provided here because this is the most common application for which problems have been reported.
    981         </p><p><a class="indexterm" name="id2624988"></a><a class="indexterm" name="id2624996"></a>
     981        </p><p><a class="indexterm" name="id2625012"></a><a class="indexterm" name="id2625020"></a>
    982982        Common applications that are affected by client- and server-side locking controls include MS
    983983        Excel and Act!. Important locking guidance is provided here.
    984         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625009"></a>Microsoft Access</h3></div></div></div><p>
     984        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625032"></a>Microsoft Access</h3></div></div></div><p>
    985985        The best advice that can be given is to carefully read the Microsoft knowledgebase articles that
    986986        cover this area. Examples of relevant documents include:
    987         </p><div class="itemizedlist"><ul type="disc"><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;208778</p></li><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;299373</p></li></ul></div><p><a class="indexterm" name="id2625036"></a><a class="indexterm" name="id2625048"></a>
     987        </p><div class="itemizedlist"><ul type="disc"><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;208778</p></li><li><p>http://support.microsoft.com/default.aspx?scid=kb;en-us;299373</p></li></ul></div><p><a class="indexterm" name="id2625059"></a><a class="indexterm" name="id2625071"></a>
    988988        Make sure that your MS Access database file is configured for multiuser access (not set for
    989989        exclusive open). Open MS Access on each client workstation, then set the following: <span class="guimenu">(Menu bar) Tools</span>+<span class="guimenu">Options</span>+<span class="guimenu">[tab] General</span>.  Set network path to Default database folder: <code class="filename">\\server\share\folder</code>.
    990990        </p><p>
    991991        You can configure MS Access file sharing behavior as follows: click <span class="guimenu">[tab] Advanced</span>.
    992           Set:<a class="indexterm" name="id2625098"></a>
    993         </p><div class="itemizedlist"><ul type="disc"><li><p>Default open mode: Shared</p></li><li><p>Default Record Locking: Edited Record</p></li><li><p>Open databases using record_level locking</p></li></ul></div><p><a class="indexterm" name="id2625128"></a>
     992          Set:<a class="indexterm" name="id2625122"></a>
     993        </p><div class="itemizedlist"><ul type="disc"><li><p>Default open mode: Shared</p></li><li><p>Default Record Locking: Edited Record</p></li><li><p>Open databases using record_level locking</p></li></ul></div><p><a class="indexterm" name="id2625151"></a>
    994994        You must now commit the changes so that they will take effect. To do so, click
    995995        <span class="guimenu">Apply</span><span class="guimenu">Ok</span>. At this point, you should exit MS Access, restart
    996996        it, and then validate that these settings have not changed.
    997         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625156"></a>Act! Database Sharing</h3></div></div></div><p><a class="indexterm" name="id2625163"></a><a class="indexterm" name="id2625171"></a>
     997        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625180"></a>Act! Database Sharing</h3></div></div></div><p><a class="indexterm" name="id2625186"></a><a class="indexterm" name="id2625194"></a>
    998998        Where the server sharing the ACT! database(s) is running Samba,or Windows NT, 200x, or XP, you
    999999        must disable opportunistic locking on the server and all workstations. Failure to do so
     
    10031003        as well as from article
    10041004        <a class="ulink" href="http://itdomino.saleslogix.com/act.nsf/docid/200110485036" target="_top">200110485036</a>.
    1005         </p><p><a class="indexterm" name="id2625201"></a><a class="indexterm" name="id2625210"></a>
     1005        </p><p><a class="indexterm" name="id2625225"></a><a class="indexterm" name="id2625233"></a>
    10061006        These documents clearly state that opportunistic locking must be disabled on both
    10071007        the server (Samba in the case we are interested in here), as well as on every workstation
     
    10111011        Registered Act! users may download this utility from the Act! Web
    10121012        <a class="ulink" href="http://www.act.com/support/updates/index.cfm" target="_top">site.</a>
    1013         </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625241"></a>Opportunistic Locking Controls</h3></div></div></div><p><a class="indexterm" name="id2625248"></a>
     1013        </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625264"></a>Opportunistic Locking Controls</h3></div></div></div><p><a class="indexterm" name="id2625271"></a>
    10141014        Third-party Windows applications may not be compatible with the use of opportunistic file
    1015         and record locking. For applications that are known not to be compatible,<sup>[<a name="id2625260" href="#ftn.id2625260" class="footnote">14</a>]</sup> oplock
     1015        and record locking. For applications that are known not to be compatible,<sup>[<a name="id2625283" href="#ftn.id2625283" class="footnote">14</a>]</sup> oplock
    10161016        support may need to be disabled both on the Samba server and on the Windows workstations.
    1017         </p><p><a class="indexterm" name="id2625274"></a><a class="indexterm" name="id2625282"></a><a class="indexterm" name="id2625290"></a>
     1017        </p><p><a class="indexterm" name="id2625297"></a><a class="indexterm" name="id2625305"></a><a class="indexterm" name="id2625313"></a>
    10181018        Oplocks enable a Windows client to cache parts of a file that are being
    10191019        edited. Another windows client may then request to open the file with the
     
    10221022        doing so, that workstation must flush the file from cache memory to the
    10231023        disk or network drive.
    1024         </p><p><a class="indexterm" name="id2625311"></a>
     1024        </p><p><a class="indexterm" name="id2625334"></a>
    10251025        Disabling of Oplocks usage may require server and client changes.
    10261026        Oplocks may be disabled by file, by file pattern, on the share, or on the
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/ch14.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 14. Samba Support</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"><link rel="next" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 14. Samba Support</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="HA.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="appendix.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en-US"><div class="titlepage"><div><div><h2 class="title"><a name="id2620871"></a>Chapter 14. Samba Support</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="ch14.html#id2621002">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621220">Commercial Support</a></span></dt></dl></div><p>
    2 <a class="indexterm" name="id2620880"></a>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 14. Samba Support</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="HA.html" title="Chapter 13. Performance, Reliability, and Availability"><link rel="next" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 14. Samba Support</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="HA.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="appendix.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en-US"><div class="titlepage"><div><div><h2 class="title"><a name="id2620898"></a>Chapter 14. Samba Support</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="ch14.html#id2621028">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621247">Commercial Support</a></span></dt></dl></div><p>
     2<a class="indexterm" name="id2620907"></a>
    33One of the most difficult to answer questions in the information technology industry is, &#8220;<span class="quote">What is
    44support?</span>&#8221;. That question irritates some folks, as much as common answers may annoy others.
    55</p><p>
    6 <a class="indexterm" name="id2620897"></a>
     6<a class="indexterm" name="id2620924"></a>
    77The most aggravating situation pertaining to support is typified when, as a Linux user, a call is made to
    88an Internet service provider who, instead of listening to the problem to find a solution, blandly replies:
     
    1616inconvenience, loss of productivity, disorientation, uncertainty, and real or perceived risk.
    1717</p><p>
    18 <a class="indexterm" name="id2620928"></a>
    19 <a class="indexterm" name="id2620935"></a>
    20 <a class="indexterm" name="id2620942"></a>
     18<a class="indexterm" name="id2620954"></a>
     19<a class="indexterm" name="id2620961"></a>
     20<a class="indexterm" name="id2620968"></a>
    2121One of the forces that has become a driving force for the adoption of open source software is the fact that
    2222many IT businesses have provided services that have perhaps failed to deliver what the customer expected, or
    2323that have been found wanting for other reasons.
    2424</p><p>
    25 <a class="indexterm" name="id2620956"></a>
    26 <a class="indexterm" name="id2620963"></a>
     25<a class="indexterm" name="id2620983"></a>
     26<a class="indexterm" name="id2620990"></a>
    2727In recognition of the need for needs satisfaction as the primary experience an information technology user or
    2828consumer expects, the information provided in this chapter may help someone to avoid an unpleasant experience
    2929in respect of problem resolution.
    3030</p><p>
    31 <a class="indexterm" name="id2620978"></a>
    32 <a class="indexterm" name="id2620985"></a>
    33 <a class="indexterm" name="id2620992"></a>
     31<a class="indexterm" name="id2621004"></a>
     32<a class="indexterm" name="id2621011"></a>
     33<a class="indexterm" name="id2621018"></a>
    3434In the open source software arena there are two support options: free support and paid-for (commercial)
    3535support.
    36 </p><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621002"></a>Free Support</h2></div></div></div><p>
    37 <a class="indexterm" name="id2621009"></a>
    38 <a class="indexterm" name="id2621016"></a>
    39 <a class="indexterm" name="id2621023"></a>
    40 <a class="indexterm" name="id2621030"></a>
    41 <a class="indexterm" name="id2621037"></a>
    42 <a class="indexterm" name="id2621044"></a>
     36</p><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621028"></a>Free Support</h2></div></div></div><p>
     37<a class="indexterm" name="id2621036"></a>
     38<a class="indexterm" name="id2621043"></a>
     39<a class="indexterm" name="id2621050"></a>
     40<a class="indexterm" name="id2621057"></a>
     41<a class="indexterm" name="id2621064"></a>
     42<a class="indexterm" name="id2621071"></a>
    4343        Free support may be obtained from friends, colleagues, user groups, mailing lists, and interactive help
    4444        facilities. An example of an interactive dacility is the Internet relay chat (IRC) channels that host user
    4545        supported mutual assistance.
    4646        </p><p>
    47 <a class="indexterm" name="id2621058"></a>
    48 <a class="indexterm" name="id2621065"></a>
    49 <a class="indexterm" name="id2621072"></a>
    50 <a class="indexterm" name="id2621079"></a>
    51 <a class="indexterm" name="id2621086"></a>
     47<a class="indexterm" name="id2621085"></a>
     48<a class="indexterm" name="id2621092"></a>
     49<a class="indexterm" name="id2621099"></a>
     50<a class="indexterm" name="id2621106"></a>
     51<a class="indexterm" name="id2621112"></a>
    5252        The Samba project maintains a mailing list that is commonly used to discuss solutions to Samba deployments.
    5353        Information regarding subscription to the Samba mailing list can be found on the Samba <a class="ulink" href="https://lists.samba.org/mailman/" target="_top">web</a> site. The public mailing list that can be used to obtain
     
    5656        the Samba <a class="ulink" href="http://www.samba.org/samba.irc.html" target="_top">IRC</a> web page.
    5757        </p><p>
    58 <a class="indexterm" name="id2621127"></a>
    59 <a class="indexterm" name="id2621134"></a>
    60 <a class="indexterm" name="id2621141"></a>
    61 <a class="indexterm" name="id2621148"></a>
     58<a class="indexterm" name="id2621154"></a>
     59<a class="indexterm" name="id2621161"></a>
     60<a class="indexterm" name="id2621168"></a>
     61<a class="indexterm" name="id2621175"></a>
    6262        As a general rule, it is considered poor net behavior to contact a Samba Team member directly
    6363        for free support. Most active members of the Samba Team work exceptionally long hours to assist
     
    6767        to show appropriate discretion and reservation in all direct contact.
    6868        </p><p>
    69 <a class="indexterm" name="id2621168"></a>
    70 <a class="indexterm" name="id2621174"></a>
    71 <a class="indexterm" name="id2621181"></a>
     69<a class="indexterm" name="id2621194"></a>
     70<a class="indexterm" name="id2621201"></a>
     71<a class="indexterm" name="id2621208"></a>
    7272        When you stumble across a Samba bug, often the quickest way to get it resolved is by posting
    7373        a bug <a class="ulink" href="https://bugzilla.samba.org/" target="_top">report</a>. All such reports are mailed to
     
    7777        that will permit the problem to be reproduced.
    7878        </p><p>
    79 <a class="indexterm" name="id2621206"></a>
     79<a class="indexterm" name="id2621232"></a>
    8080        We all recognize that sometimes free support does not provide the answer that is sought within
    8181        the time-frame required. At other times the problem is elusive and you may lack the experience
    8282        necessary to isolate the problem and thus to resolve it. This is a situation where is may be
    8383        prudent to purchase paid-for support.
    84         </p></div><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621220"></a>Commercial Support</h2></div></div></div><p>
     84        </p></div><div class="sect1" lang="en-US"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2621247"></a>Commercial Support</h2></div></div></div><p>
    8585        There are six basic support oriented services that are most commonly sought by Samba sites:
    8686        </p><div class="itemizedlist"><ul type="disc"><li><p>Assistance with network design</p></li><li><p>Staff Training</p></li><li><p>Assistance with Samba network deployment and installation</p></li><li><p>Priority telephone or email Samba configuration assistance</p></li><li><p>Trouble-shooting and diagnostic assistance</p></li><li><p>Provision of quality assured ready-to-install Samba binary packages</p></li></ul></div><p>
    87 <a class="indexterm" name="id2621267"></a>
    88 <a class="indexterm" name="id2621274"></a>
     87<a class="indexterm" name="id2621294"></a>
     88<a class="indexterm" name="id2621301"></a>
    8989        Information regarding companies that provide professional Samba support can be obtained by performing a Google
    9090        search, as well as by reference to the Samba <a class="ulink" href="http://www.samba.org/samba/support.html" target="_top">Support</a> web page. Companies who notify the Samba Team
     
    9494        them.
    9595        </p><p>
    96 <a class="indexterm" name="id2621300"></a>
     96<a class="indexterm" name="id2621326"></a>
    9797        The policy within the Samba Team is to treat all commercial support providers equally and to show no
    9898        preference. As a result, Samba Team members who provide commercial support are lumped in with everyone else.
     
    100100        is pro-community; so do what you can to help a local business to prosper.
    101101        </p><p>
    102 <a class="indexterm" name="id2621317"></a>
     102<a class="indexterm" name="id2621343"></a>
    103103        Open source software support can be found in any quality, at any price and in any place you can
    104104        to obtain it. Over 180 companies around the world provide Samba support, there is no excuse for
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/go01.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Glossary</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="apa.html" title="Appendix A.  GNU General Public License version 3"><link rel="next" href="ix01.html" title="Index"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Glossary</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="apa.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="ix01.html">Next</a></td></tr></table><hr></div><div class="glossary"><div class="titlepage"><div><div><h2 class="title"><a name="id2630357"></a>Glossary</h2></div></div></div><dl><dt>Access Control List</dt><dd><p>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Glossary</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="apa.html" title="Appendix A.  GNU General Public License version 3"><link rel="next" href="ix01.html" title="Index"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Glossary</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="apa.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="ix01.html">Next</a></td></tr></table><hr></div><div class="glossary"><div class="titlepage"><div><div><h2 class="title"><a name="id2630385"></a>Glossary</h2></div></div></div><dl><dt>Access Control List</dt><dd><p>
    22                A detailed list of permissions granted to users or groups with respect to file and network
    33                resource access.
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/index.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Samba-3 by Example</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="next" href="pr01.html" title="About the Cover Artwork"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Samba-3 by Example</th></tr><tr><td width="20%" align="left"> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="pr01.html">Next</a></td></tr></table><hr></div><div class="book" lang="en"><div class="titlepage"><div><div><h1 class="title"><a name="S3bE"></a>Samba-3 by Example</h1></div><div><h2 class="subtitle">Practical Exercises in Successful Samba Deployment</h2></div><div><div class="authorgroup"><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>&gt;</code></p></div></div></div></div></div><div><p class="pubdate">July, 2006</p></div></div><hr></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="preface"><a href="pr01.html">About the Cover Artwork</a></span></dt><dt><span class="preface"><a href="pr02.html">Acknowledgments</a></span></dt><dt><span class="preface"><a href="pr03.html">Foreword</a></span></dt><dd><dl><dt><span class="sect1"><a href="pr03.html#id2501076">By John M. Weathersby, Executive Director, OSSI</a></span></dt></dl></dd><dt><span class="preface"><a href="preface.html">Preface</a></span></dt><dd><dl><dt><span class="sect1"><a href="preface.html#id2501265">Why Is This Book Necessary?</a></span></dt><dd><dl><dt><span class="sect2"><a href="preface.html#id2498988">Samba 3.0.20 Update Edition</a></span></dt></dl></dd><dt><span class="sect1"><a href="preface.html#id2498874">Prerequisites</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498906">Approach</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498971">Summary of Topics</a></span></dt><dt><span class="sect1"><a href="preface.html#id2550668">Conventions Used</a></span></dt></dl></dd><dt><span class="part"><a href="ExNetworks.html">I. Example Network Configurations</a></span></dt><dd><dl><dt><span class="chapter"><a href="simple.html">1. No-Frills Samba Servers</a></span></dt><dd><dl><dt><span class="sect1"><a href="simple.html#id2550864">Introduction</a></span></dt><dt><span class="sect1"><a href="simple.html#id2550904">Assignment Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="simple.html#id2550946">Drafting Office</a></span></dt><dt><span class="sect2"><a href="simple.html#id2551655">Charity Administration Office</a></span></dt><dt><span class="sect2"><a href="simple.html#AccountingOffice">Accounting Office</a></span></dt></dl></dd><dt><span class="sect1"><a href="simple.html#id2554992">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="small.html">2. Small Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="small.html#id2555462">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555484">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555545">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555593">Technical Issues</a></span></dt><dt><span class="sect2"><a href="small.html#id2555791">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555812">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2557356">Validation</a></span></dt><dt><span class="sect2"><a href="small.html#id2558004">Notebook Computers: A Special Case</a></span></dt><dt><span class="sect2"><a href="small.html#id2558030">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2558104">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="secure.html">3. Secure Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="secure.html#id2558582">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558634">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2558867">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="secure.html#id2559309">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2559348">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#ch4bsc">Basic System Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2560202">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4ptrcfg">Printer Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4valid">Validation</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4appscfg">Application Share Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2564663">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2564725">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="Big500users.html">4. The 500-User Office</a></span></dt><dd><dl><dt><span class="sect1"><a href="Big500users.html#id2565247">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565292">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565398">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565433">Technical Issues</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2565636">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565659">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#ch5-dnshcp-setup">Installation of DHCP, DNS, and Samba Control Files</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566387">Server Preparation: All Servers</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566951">Server-Specific Preparation</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5-procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2570151">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2570210">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="happy.html">5. Making Happy Users</a></span></dt><dd><dl><dt><span class="sect1"><a href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></span></dt><dt><span class="sect1"><a href="happy.html#id2571190">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571288">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2571425">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573760">Political Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573776">Installation Checklist</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2573956">Samba Server Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-ptrcfg">Printer Configuration</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a></span></dt><dt><span class="sect1"><a href="happy.html#id2580803">Miscellaneous Server Preparation Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2580823">Configuring Directory Share Point Roots</a></span></dt><dt><span class="sect2"><a href="happy.html#id2580918">Configuring Profile Directories</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581163">Preparation of Logon Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581274">Assigning User Rights and Privileges</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2581407">Windows Client Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583160">Software Installation</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583195">Roll-out Image Creation</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2583229">Key Points Learned</a></span></dt><dt><span class="sect1"><a href="happy.html#id2583345">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="2000users.html">6. A Distributed 2000-User Network</a></span></dt><dd><dl><dt><span class="sect1"><a href="2000users.html#id2583767">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2583797">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2583865">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2584139">Technical Issues</a></span></dt><dt><span class="sect2"><a href="2000users.html#id2585083">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2585101">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2588260">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2588407">Questions and Answers</a></span></dt></dl></dd></dl></dd><dt><span class="part"><a href="DMSMig.html">II. Domain Members, Updating Samba and Migration</a></span></dt><dd><dl><dt><span class="chapter"><a href="unixclients.html">7. Adding Domain Member Servers and Clients</a></span></dt><dd><dl><dt><span class="sect1"><a href="unixclients.html#id2589266">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589319">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2589354">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589383">Technical Issues</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2590032">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2590132">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></span></dt><dt><span class="sect2"><a href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></span></dt><dt><span class="sect2"><a href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a></span></dt><dt><span class="sect2"><a href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596913">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2596967">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="upgrades.html">8. Updating Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="upgrades.html#id2598126">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2598223">Cautions and Notes</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2599552">Upgrading from Samba 1.x and 2.x to Samba-3</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2600546">Samba-3 to Samba-3 Updates on the Same Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600749">Migrating Samba-3 to a New Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="ntmigration.html">9. Migrating NT4 Domain to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="ntmigration.html#id2601336">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601421">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2601476">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601662">Technical Issues</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2601985">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2602011">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2605017">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2605055">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="nw4migration.html">10. Migrating NetWare Server to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="nw4migration.html#id2606030">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606147">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606260">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606337">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606527">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606536">NetWare Migration Using LDAP Backend</a></span></dt></dl></dd></dl></dd></dl></dd><dt><span class="part"><a href="RefSection.html">III. Reference Section</a></span></dt><dd><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615399">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615533">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616162">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616193">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616294">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616327">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616483">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616500">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618352">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618413">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618932">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619019">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619520">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2619995">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620323">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620398">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620470">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620570">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620728">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620832">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621002">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621220">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621928">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622349">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622695">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622707">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622755">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622895">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622954">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623532">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624529">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625009">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625156">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625241">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625407">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625568">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625629">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625745">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625871">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628089">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628204">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A.
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Samba-3 by Example</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="next" href="pr01.html" title="About the Cover Artwork"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Samba-3 by Example</th></tr><tr><td width="20%" align="left"> </td><th width="60%" align="center"> </th><td width="20%" align="right"> <a accesskey="n" href="pr01.html">Next</a></td></tr></table><hr></div><div class="book" lang="en"><div class="titlepage"><div><div><h1 class="title"><a name="S3bE"></a>Samba-3 by Example</h1></div><div><h2 class="subtitle">Practical Exercises in Successful Samba Deployment</h2></div><div><div class="authorgroup"><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="orgname">Samba Team</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email">&lt;<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>&gt;</code></p></div></div></div></div></div><div><p class="pubdate">July, 2006</p></div></div><hr></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="preface"><a href="pr01.html">About the Cover Artwork</a></span></dt><dt><span class="preface"><a href="pr02.html">Acknowledgments</a></span></dt><dt><span class="preface"><a href="pr03.html">Foreword</a></span></dt><dd><dl><dt><span class="sect1"><a href="pr03.html#id2501076">By John M. Weathersby, Executive Director, OSSI</a></span></dt></dl></dd><dt><span class="preface"><a href="preface.html">Preface</a></span></dt><dd><dl><dt><span class="sect1"><a href="preface.html#id2501265">Why Is This Book Necessary?</a></span></dt><dd><dl><dt><span class="sect2"><a href="preface.html#id2498988">Samba 3.0.20 Update Edition</a></span></dt></dl></dd><dt><span class="sect1"><a href="preface.html#id2498874">Prerequisites</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498906">Approach</a></span></dt><dt><span class="sect1"><a href="preface.html#id2498971">Summary of Topics</a></span></dt><dt><span class="sect1"><a href="preface.html#id2550668">Conventions Used</a></span></dt></dl></dd><dt><span class="part"><a href="ExNetworks.html">I. Example Network Configurations</a></span></dt><dd><dl><dt><span class="chapter"><a href="simple.html">1. No-Frills Samba Servers</a></span></dt><dd><dl><dt><span class="sect1"><a href="simple.html#id2550864">Introduction</a></span></dt><dt><span class="sect1"><a href="simple.html#id2550904">Assignment Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="simple.html#id2550946">Drafting Office</a></span></dt><dt><span class="sect2"><a href="simple.html#id2551655">Charity Administration Office</a></span></dt><dt><span class="sect2"><a href="simple.html#AccountingOffice">Accounting Office</a></span></dt></dl></dd><dt><span class="sect1"><a href="simple.html#id2554992">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="small.html">2. Small Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="small.html#id2555462">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555484">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555545">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2555593">Technical Issues</a></span></dt><dt><span class="sect2"><a href="small.html#id2555791">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2555812">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="small.html#id2557356">Validation</a></span></dt><dt><span class="sect2"><a href="small.html#id2558004">Notebook Computers: A Special Case</a></span></dt><dt><span class="sect2"><a href="small.html#id2558030">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="small.html#id2558104">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="secure.html">3. Secure Office Networking</a></span></dt><dd><dl><dt><span class="sect1"><a href="secure.html#id2558582">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558634">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2558867">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#id2558882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="secure.html#id2559309">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2559348">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="secure.html#ch4bsc">Basic System Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2560202">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4ptrcfg">Printer Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4valid">Validation</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4appscfg">Application Share Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#ch4wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="secure.html#id2564663">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="secure.html#id2564725">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="Big500users.html">4. The 500-User Office</a></span></dt><dd><dl><dt><span class="sect1"><a href="Big500users.html#id2565247">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565292">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565398">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#id2565433">Technical Issues</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2565636">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2565659">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="Big500users.html#ch5-dnshcp-setup">Installation of DHCP, DNS, and Samba Control Files</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566387">Server Preparation: All Servers</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2566951">Server-Specific Preparation</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5-procstart">Process Startup Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#ch5wincfg">Windows Client Configuration</a></span></dt><dt><span class="sect2"><a href="Big500users.html#id2570151">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="Big500users.html#id2570210">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="happy.html">5. Making Happy Users</a></span></dt><dd><dl><dt><span class="sect1"><a href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></span></dt><dt><span class="sect1"><a href="happy.html#id2571190">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571288">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2571425">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2571882">Technical Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573760">Political Issues</a></span></dt><dt><span class="sect2"><a href="happy.html#id2573776">Installation Checklist</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2573956">Samba Server Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></span></dt><dt><span class="sect2"><a href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></span></dt><dt><span class="sect2"><a href="happy.html#sbehap-ptrcfg">Printer Configuration</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a></span></dt><dt><span class="sect1"><a href="happy.html#id2580803">Miscellaneous Server Preparation Tasks</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#id2580823">Configuring Directory Share Point Roots</a></span></dt><dt><span class="sect2"><a href="happy.html#id2580918">Configuring Profile Directories</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581163">Preparation of Logon Scripts</a></span></dt><dt><span class="sect2"><a href="happy.html#id2581274">Assigning User Rights and Privileges</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2581407">Windows Client Configuration</a></span></dt><dd><dl><dt><span class="sect2"><a href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a></span></dt><dt><span class="sect2"><a href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583160">Software Installation</a></span></dt><dt><span class="sect2"><a href="happy.html#id2583195">Roll-out Image Creation</a></span></dt></dl></dd><dt><span class="sect1"><a href="happy.html#id2583229">Key Points Learned</a></span></dt><dt><span class="sect1"><a href="happy.html#id2583345">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="2000users.html">6. A Distributed 2000-User Network</a></span></dt><dd><dl><dt><span class="sect1"><a href="2000users.html#id2583767">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2583797">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2583865">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2584139">Technical Issues</a></span></dt><dt><span class="sect2"><a href="2000users.html#id2585083">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2585101">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="2000users.html#id2588260">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="2000users.html#id2588407">Questions and Answers</a></span></dt></dl></dd></dl></dd><dt><span class="part"><a href="DMSMig.html">II. Domain Members, Updating Samba and Migration</a></span></dt><dd><dl><dt><span class="chapter"><a href="unixclients.html">7. Adding Domain Member Servers and Clients</a></span></dt><dd><dl><dt><span class="sect1"><a href="unixclients.html#id2589266">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589319">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2589354">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#id2589383">Technical Issues</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2590032">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2590132">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></span></dt><dt><span class="sect2"><a href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></span></dt><dt><span class="sect2"><a href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a></span></dt><dt><span class="sect2"><a href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></span></dt><dt><span class="sect2"><a href="unixclients.html#id2596913">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="unixclients.html#id2596967">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="upgrades.html">8. Updating Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="upgrades.html#id2598126">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2598223">Cautions and Notes</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2599552">Upgrading from Samba 1.x and 2.x to Samba-3</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></span></dt></dl></dd><dt><span class="sect1"><a href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></span></dt><dd><dl><dt><span class="sect2"><a href="upgrades.html#id2600546">Samba-3 to Samba-3 Updates on the Same Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2600749">Migrating Samba-3 to a New Server</a></span></dt><dt><span class="sect2"><a href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="ntmigration.html">9. Migrating NT4 Domain to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="ntmigration.html#id2601336">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601421">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2601476">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2601662">Technical Issues</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2601985">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2602011">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></span></dt><dt><span class="sect2"><a href="ntmigration.html#id2605017">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="ntmigration.html#id2605055">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="nw4migration.html">10. Migrating NetWare Server to Samba-3</a></span></dt><dd><dl><dt><span class="sect1"><a href="nw4migration.html#id2606030">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606147">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606260">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606337">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="nw4migration.html#id2606527">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="nw4migration.html#id2606536">NetWare Migration Using LDAP Backend</a></span></dt></dl></dd></dl></dd></dl></dd><dt><span class="part"><a href="RefSection.html">III. Reference Section</a></span></dt><dd><dl><dt><span class="chapter"><a href="kerberos.html">11. Active Directory, Kerberos, and Security</a></span></dt><dd><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615408">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615543">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="DomApps.html">12. Integrating Additional Services</a></span></dt><dd><dl><dt><span class="sect1"><a href="DomApps.html#id2616172">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616202">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616313">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#id2616346">Technical Issues</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2616502">Political Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2616520">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></span></dt><dt><span class="sect2"><a href="DomApps.html#id2618372">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="DomApps.html#id2618432">Questions and Answers</a></span></dt></dl></dd><dt><span class="chapter"><a href="HA.html">13. Performance, Reliability, and Availability</a></span></dt><dd><dl><dt><span class="sect1"><a href="HA.html#id2618959">Introduction</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619057">Dissection and Discussion</a></span></dt><dt><span class="sect1"><a href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></span></dt><dd><dl><dt><span class="sect2"><a href="HA.html#id2619557">Name Resolution</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620033">Samba Configuration</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620360">Use and Location of BDCs</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620435">Use One Consistent Version of MS Windows Client</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620507">Distribute Network Load with MSDFS</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620607">Hardware Problems</a></span></dt><dt><span class="sect2"><a href="HA.html#id2620755">Large Directories</a></span></dt></dl></dd><dt><span class="sect1"><a href="HA.html#id2620859">Key Points Learned</a></span></dt></dl></dd><dt><span class="chapter"><a href="ch14.html">14. Samba Support</a></span></dt><dd><dl><dt><span class="sect1"><a href="ch14.html#id2621028">Free Support</a></span></dt><dt><span class="sect1"><a href="ch14.html#id2621247">Commercial Support</a></span></dt></dl></dd><dt><span class="chapter"><a href="appendix.html">15. A Collection of Useful Tidbits</a></span></dt><dd><dl><dt><span class="sect1"><a href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2621955">Samba System File Location</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622376">Starting Samba</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2622715">DNS Configuration Files</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622727">The Forward Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622776">The Reverse Zone File for the Loopback Adaptor</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2622916">DNS Root Server Hint File</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2622975">Initialization of the LDAP Database</a></span></dt></dl></dd><dt><span class="sect1"><a href="appendix.html#id2623561">The LDAP Account Manager</a></span></dt><dt><span class="sect1"><a href="appendix.html#id2624558">IDEALX Management Console</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></span></dt><dt><span class="sect1"><a href="appendix.html#ch12dblck">Shared Data Integrity</a></span></dt><dd><dl><dt><span class="sect2"><a href="appendix.html#id2625032">Microsoft Access</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625180">Act! Database Sharing</a></span></dt><dt><span class="sect2"><a href="appendix.html#id2625264">Opportunistic Locking Controls</a></span></dt></dl></dd></dl></dd><dt><span class="chapter"><a href="primer.html">16. Networking Primer</a></span></dt><dd><dl><dt><span class="sect1"><a href="primer.html#id2625430">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625592">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625652">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625769">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625894">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628113">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628227">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></dd><dt><span class="appendix"><a href="apa.html">A.
    22    GNU General Public License version 3
    3   </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id2628870">A.
     3  </a></span></dt><dd><dl><dt><span class="bridgehead"><a href="apa.html#id2628893">A.
    44    Preamble
    5   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629015">A.
     5  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629038">A.
    66    TERMS AND CONDITIONS
    7   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629019">A.
     7  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629042">A.
    88    0. Definitions.
    9   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629111">A.
     9  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629134">A.
    1010    1. Source Code.
    11   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629210">A.
     11  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629233">A.
    1212    2. Basic Permissions.
    13   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629249">A.
     13  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629272">A.
    1414    3. Protecting Users&#8217; Legal Rights From Anti-Circumvention Law.
    15   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629290">A.
     15  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629308">A.
    1616    4. Conveying Verbatim Copies.
    17   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629317">A.
     17  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629335">A.
    1818    5. Conveying Modified Source Versions.
    19   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629412">A.
     19  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629431">A.
    2020    6. Conveying Non-Source Forms.
    21   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629602">A.
     21  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629620">A.
    2222     7. Additional Terms.
    23    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629738">A.
     23   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629756">A.
    2424     8. Termination.
    25    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629781">A.
     25   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629800">A.
    2626     9. Acceptance Not Required for Having Copies.
    27    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629801">A.
     27   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629819">A.
    2828     10. Automatic Licensing of Downstream Recipients.
    29    </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629853">A.
     29   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629871">A.
    3030    11. Patents.
    31   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2629988">A.
     31  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630017">A.
    3232    12. No Surrender of Others&#8217; Freedom.
    33   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630010">A.
     33  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A.
    3434    13. Use with the ???TITLE??? Affero General Public License.
    35   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630039">A.
     35  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630067">A.
    3636    14. Revised Versions of this License.
    37   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630101">A.
     37  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630130">A.
    3838    15. Disclaimer of Warranty.
    39   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630128">A.
     39  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630156">A.
    4040    16. Limitation of Liability.
    41   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630148">A.
     41  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630176">A.
    4242    17. Interpretation of Sections 15 and 16.
    43   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630164">A.
     43  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630193">A.
    4444    END OF TERMS AND CONDITIONS
    45   </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630168">A.
     45  </a></span></dt><dt><span class="bridgehead"><a href="apa.html#id2630197">A.
    4646    How to Apply These Terms to Your New Programs
    4747  </a></span></dt></dl></dd></dl></dd><dt><span class="glossary"><a href="go01.html">Glossary</a></span></dt><dt><span class="index"><a href="ix01.html">Index</a></span></dt></dl></div><div class="list-of-figures"><p><b>List of Figures</b></p><dl><dt>1.1. <a href="simple.html#charitynet">Charity Administration Office Network</a></dt><dt>1.2. <a href="simple.html#acctingnet2">Accounting Office Network Topology</a></dt><dt>2.1. <a href="small.html#acct2net">Abmas Accounting  52-User Network Topology</a></dt><dt>3.1. <a href="secure.html#ch04net">Abmas Network Topology  130 Users</a></dt><dt>4.1. <a href="Big500users.html#chap05net">Network Topology  500 User Network Using tdbsam passdb backend.</a></dt><dt>5.1. <a href="happy.html#sbehap-LDAPdiag">The Interaction of LDAP, UNIX Posix Accounts and Samba Accounts</a></dt><dt>5.2. <a href="happy.html#chap6net">Network Topology  500 User Network Using ldapsam passdb backend</a></dt><dt>5.3. <a href="happy.html#XP-screen001">Windows XP Professional  User Shared Folders</a></dt><dt>6.1. <a href="2000users.html#chap7idres">Samba and Authentication Backend Search Pathways</a></dt><dt>6.2. <a href="2000users.html#ch7singleLDAP">Samba Configuration to Use a Single LDAP Server</a></dt><dt>6.3. <a href="2000users.html#ch7dualLDAP">Samba Configuration to Use a Dual (Fail-over) LDAP Server</a></dt><dt>6.4. <a href="2000users.html#ch7dualadd">Samba Configuration to Use Dual LDAP Databases - Broken - Do Not Use!</a></dt><dt>6.5. <a href="2000users.html#ch7dualok">Samba Configuration to Use Two LDAP Databases - The result is additive.</a></dt><dt>6.6. <a href="2000users.html#chap7net">Network Topology  2000 User Complex Design A</a></dt><dt>6.7. <a href="2000users.html#chap7net2">Network Topology  2000 User Complex Design B</a></dt><dt>7.1. <a href="unixclients.html#ch09openmag">Open Magazine Samba Survey</a></dt><dt>7.2. <a href="unixclients.html#ch9-sambadc">Samba Domain: Samba Member Server</a></dt><dt>7.3. <a href="unixclients.html#ch9-adsdc">Active Directory Domain: Samba Member Server</a></dt><dt>9.1. <a href="ntmigration.html#ch8-migration">Schematic Explaining the net rpc vampire Process</a></dt><dt>9.2. <a href="ntmigration.html#NT4DUM">View of Accounts in NT4 Domain User Manager</a></dt><dt>15.1. <a href="appendix.html#swxpp001">The General Panel.</a></dt><dt>15.2. <a href="appendix.html#swxpp004">The Computer Name Panel.</a></dt><dt>15.3. <a href="appendix.html#swxpp006">The Computer Name Changes Panel</a></dt><dt>15.4. <a href="appendix.html#swxpp007">The Computer Name Changes Panel  Domain MIDEARTH</a></dt><dt>15.5. <a href="appendix.html#swxpp008">Computer Name Changes  User name and Password Panel</a></dt><dt>15.6. <a href="appendix.html#lam-login">The LDAP Account Manager Login Screen</a></dt><dt>15.7. <a href="appendix.html#lam-config">The LDAP Account Manager Configuration Screen</a></dt><dt>15.8. <a href="appendix.html#lam-user">The LDAP Account Manager User Edit Screen</a></dt><dt>15.9. <a href="appendix.html#lam-group">The LDAP Account Manager Group Edit Screen</a></dt><dt>15.10. <a href="appendix.html#lam-group-mem">The LDAP Account Manager Group Membership Edit Screen</a></dt><dt>15.11. <a href="appendix.html#lam-host">The LDAP Account Manager Host Edit Screen</a></dt><dt>15.12. <a href="appendix.html#imcidealx">The IMC Samba User Account Screen</a></dt><dt>16.1. <a href="primer.html#pktcap01">Windows Me  Broadcasts  The First 10 Minutes</a></dt><dt>16.2. <a href="primer.html#pktcap02">Windows Me  Later Broadcast Sample</a></dt><dt>16.3. <a href="primer.html#hostannounce">Typical Windows 9x/Me Host Announcement</a></dt><dt>16.4. <a href="primer.html#nullconnect">Typical Windows 9x/Me NULL SessionSetUp AndX Request</a></dt><dt>16.5. <a href="primer.html#userconnect">Typical Windows 9x/Me User SessionSetUp AndX Request</a></dt><dt>16.6. <a href="primer.html#XPCap01">Typical Windows XP NULL Session Setup AndX Request</a></dt><dt>16.7. <a href="primer.html#XPCap02">Typical Windows XP User Session Setup AndX Request</a></dt></dl></div><div class="list-of-tables"><p><b>List of Tables</b></p><dl><dt>1. <a href="preface.html#pref-new">Samba Changes  3.0.2 to 3.0.20</a></dt><dt>1.1. <a href="simple.html#acctingnet">Accounting Office Network Information</a></dt><dt>3.1. <a href="secure.html#chap4netid">Abmas.US ISP Information</a></dt><dt>3.2. <a href="secure.html#namedrscfiles">DNS (named) Resource Files</a></dt><dt>4.1. <a href="Big500users.html#ch5-filelocations">Domain: MEGANET, File Locations for Servers</a></dt><dt>5.1. <a href="happy.html#sbehap-privs">Current Privilege Capabilities</a></dt><dt>5.2. <a href="happy.html#oldapreq">Required OpenLDAP Linux Packages</a></dt><dt>5.3. <a href="happy.html#sbehap-bigacct">Abmas Network Users and Groups</a></dt><dt>5.4. <a href="happy.html#proffold">Default Profile Redirections</a></dt><dt>9.1. <a href="ntmigration.html#ch8-vampire">Samba smb.conf Scripts Essential to Samba Operation</a></dt><dt>13.1. <a href="HA.html#ProbList">Effect of Common Problems</a></dt><dt>16.1. <a href="primer.html#capsstats01">Windows Me  Startup Broadcast Capture Statistics</a></dt><dt>16.2. <a href="primer.html#capsstats02">Second Machine (Windows 98)  Capture Statistics</a></dt></dl></div><div class="list-of-examples"><p><b>List of Examples</b></p><dl><dt>1.1. <a href="simple.html#draft-smbconf">Drafting Office smb.conf File</a></dt><dt>1.2. <a href="simple.html#charity-smbconfnew">Charity Administration Office smb.conf New-style File</a></dt><dt>1.3. <a href="simple.html#charity-smbconf">Charity Administration Office smb.conf Old-style File</a></dt><dt>1.4. <a href="simple.html#MEreg">Windows Me  Registry Edit File: Disable Password Caching</a></dt><dt>1.5. <a href="simple.html#acctconf">Accounting Office Network smb.conf Old Style Configuration File</a></dt><dt>2.1. <a href="small.html#initGrps">Script to Map Windows NT Groups to UNIX Groups</a></dt><dt>2.2. <a href="small.html#dhcp01">Abmas Accounting DHCP Server Configuration File  /etc/dhcpd.conf</a></dt><dt>2.3. <a href="small.html#acct2conf">Accounting Office Network smb.conf File  [globals] Section</a></dt><dt>2.4. <a href="small.html#acct3conf">Accounting Office Network smb.conf File  Services and Shares Section</a></dt><dt>3.1. <a href="secure.html#ch4memoryest">Estimation of Memory Requirements</a></dt><dt>3.2. <a href="secure.html#ch4diskest">Estimation of Disk Storage Requirements</a></dt><dt>3.3. <a href="secure.html#ch4natfw">NAT Firewall Configuration Script</a></dt><dt>3.4. <a href="secure.html#promisnet">130 User Network with tdbsam  [globals] Section</a></dt><dt>3.5. <a href="secure.html#promisnetsvca">130 User Network with tdbsam  Services Section Part A</a></dt><dt>3.6. <a href="secure.html#promisnetsvcb">130 User Network with tdbsam  Services Section Part B</a></dt><dt>3.7. <a href="secure.html#ch4initGrps">Script to Map Windows NT Groups to UNIX Groups</a></dt><dt>3.8. <a href="secure.html#prom-dhcp">DHCP Server Configuration File  /etc/dhcpd.conf</a></dt><dt>3.9. <a href="secure.html#ch4namedcfg">DNS Master Configuration File  /etc/named.conf Master Section</a></dt><dt>3.10. <a href="secure.html#ch4namedvarfwd">DNS Master Configuration File  /etc/named.conf Forward Lookup Definition Section</a></dt><dt>3.11. <a href="secure.html#ch4namedvarrev">DNS Master Configuration File  /etc/named.conf Reverse Lookup Definition Section</a></dt><dt>3.12. <a href="secure.html#eth1zone">DNS 192.168.1 Reverse Zone File</a></dt><dt>3.13. <a href="secure.html#eth2zone">DNS 192.168.2 Reverse Zone File</a></dt><dt>3.14. <a href="secure.html#abmasbiz">DNS Abmas.biz Forward Zone File</a></dt><dt>3.15. <a href="secure.html#abmasus">DNS Abmas.us Forward Zone File</a></dt><dt>4.1. <a href="Big500users.html#ch5-massivesmb">Server: MASSIVE (PDC), File: /etc/samba/smb.conf</a></dt><dt>4.2. <a href="Big500users.html#ch5-dc-common">Server: MASSIVE (PDC), File: /etc/samba/dc-common.conf</a></dt><dt>4.3. <a href="Big500users.html#ch5-commonsmb">Common Samba Configuration File: /etc/samba/common.conf</a></dt><dt>4.4. <a href="Big500users.html#ch5-bldg1-smb">Server: BLDG1 (Member), File: smb.conf</a></dt><dt>4.5. <a href="Big500users.html#ch5-bldg2-smb">Server: BLDG2 (Member), File: smb.conf</a></dt><dt>4.6. <a href="Big500users.html#ch5-dommem-smb">Common Domain Member Include File: dom-mem.conf</a></dt><dt>4.7. <a href="Big500users.html#massive-dhcp">Server: MASSIVE, File: dhcpd.conf</a></dt><dt>4.8. <a href="Big500users.html#bldg1dhcp">Server: BLDG1, File: dhcpd.conf</a></dt><dt>4.9. <a href="Big500users.html#bldg2dhcp">Server: BLDG2, File: dhcpd.conf</a></dt><dt>4.10. <a href="Big500users.html#massive-nameda">Server: MASSIVE, File: named.conf, Part: A</a></dt><dt>4.11. <a href="Big500users.html#massive-namedb">Server: MASSIVE, File: named.conf, Part: B</a></dt><dt>4.12. <a href="Big500users.html#massive-namedc">Server: MASSIVE, File: named.conf, Part: C</a></dt><dt>4.13. <a href="Big500users.html#abmasbizdns">Forward Zone File: abmas.biz.hosts</a></dt><dt>4.14. <a href="Big500users.html#abmasusdns">Forward Zone File: abmas.biz.hosts</a></dt><dt>4.15. <a href="Big500users.html#bldg12nameda">Servers: BLDG1/BLDG2, File: named.conf, Part: A</a></dt><dt>4.16. <a href="Big500users.html#bldg12namedb">Servers: BLDG1/BLDG2, File: named.conf, Part: B</a></dt><dt>4.17. <a href="Big500users.html#ch5-initgrps">Initialize Groups Script, File: /etc/samba/initGrps.sh</a></dt><dt>5.1. <a href="happy.html#sbehap-dbconf">LDAP DB_CONFIG File</a></dt><dt>5.2. <a href="happy.html#sbehap-slapdconf">LDAP Master Configuration File  /etc/openldap/slapd.conf Part A</a></dt><dt>5.3. <a href="happy.html#sbehap-slapdconf2">LDAP Master Configuration File  /etc/openldap/slapd.conf Part B</a></dt><dt>5.4. <a href="happy.html#sbehap-nss01">Configuration File for NSS LDAP Support  /etc/ldap.conf</a></dt><dt>5.5. <a href="happy.html#sbehap-nss02">Configuration File for NSS LDAP Clients Support  /etc/ldap.conf</a></dt><dt>5.6. <a href="happy.html#sbehap-massive-smbconfa">LDAP Based smb.conf File, Server: MASSIVE  global Section: Part A</a></dt><dt>5.7. <a href="happy.html#sbehap-massive-smbconfb">LDAP Based smb.conf File, Server: MASSIVE  global Section: Part B</a></dt><dt>5.8. <a href="happy.html#sbehap-bldg1-smbconf">LDAP Based smb.conf File, Server: BLDG1</a></dt><dt>5.9. <a href="happy.html#sbehap-bldg2-smbconf">LDAP Based smb.conf File, Server: BLDG2</a></dt><dt>5.10. <a href="happy.html#sbehap-shareconfa">LDAP Based smb.conf File, Shares Section  Part A</a></dt><dt>5.11. <a href="happy.html#sbehap-shareconfb">LDAP Based smb.conf File, Shares Section  Part B</a></dt><dt>5.12. <a href="happy.html#sbehap-ldifadd">LDIF IDMAP Add-On Load File  File: /etc/openldap/idmap.LDIF</a></dt><dt>6.1. <a href="2000users.html#ch7-LDAP-master">LDAP Master Server Configuration File  /etc/openldap/slapd.conf</a></dt><dt>6.2. <a href="2000users.html#ch7-LDAP-slave">LDAP Slave Configuration File  /etc/openldap/slapd.conf</a></dt><dt>6.3. <a href="2000users.html#ch7-massmbconfA">Primary Domain Controller smb.conf File  Part A</a></dt><dt>6.4. <a href="2000users.html#ch7-massmbconfB">Primary Domain Controller smb.conf File  Part B</a></dt><dt>6.5. <a href="2000users.html#ch7-massmbconfC">Primary Domain Controller smb.conf File  Part C</a></dt><dt>6.6. <a href="2000users.html#ch7-slvsmbocnfA">Backup Domain Controller smb.conf File  Part A</a></dt><dt>6.7. <a href="2000users.html#ch7-slvsmbocnfB">Backup Domain Controller smb.conf File  Part B</a></dt><dt>7.1. <a href="unixclients.html#ch9-sdmsdc">Samba Domain Member in Samba Domain Using LDAP  smb.conf File</a></dt><dt>7.2. <a href="unixclients.html#ch9-ldifadd">LDIF IDMAP Add-On Load File  File: /etc/openldap/idmap.LDIF</a></dt><dt>7.3. <a href="unixclients.html#ch9-sdmlcnf">Configuration File for NSS LDAP Support  /etc/ldap.conf</a></dt><dt>7.4. <a href="unixclients.html#ch9-sdmnss">NSS using LDAP for Identity Resolution  File: /etc/nsswitch.conf</a></dt><dt>7.5. <a href="unixclients.html#ch0-NT4DSDM">Samba Domain Member Server Using Winbind smb.conf File for NT4 Domain</a></dt><dt>7.6. <a href="unixclients.html#ch0-NT4DSCM">Samba Domain Member Server Using Local Accounts smb.conf File for NT4 Domain</a></dt><dt>7.7. <a href="unixclients.html#ch9-adssdm">Samba Domain Member smb.conf File for Active Directory Membership</a></dt><dt>7.8. <a href="unixclients.html#sbe-idmapridex">Example smb.conf File Using idmap_rid</a></dt><dt>7.9. <a href="unixclients.html#sbeunxa">Typical ADS Style Domain smb.conf File</a></dt><dt>7.10. <a href="unixclients.html#sbewinbindex">ADS Membership Using RFC2307bis Identity Resolution smb.conf File</a></dt><dt>7.11. <a href="unixclients.html#ch9-pamwnbdlogin">SUSE: PAM login Module Using Winbind</a></dt><dt>7.12. <a href="unixclients.html#ch9-pamwbndxdm">SUSE: PAM xdm Module Using Winbind</a></dt><dt>7.13. <a href="unixclients.html#ch9-rhsysauth">Red Hat 9: PAM System Authentication File: /etc/pam.d/system-auth Module Using Winbind</a></dt><dt>9.1. <a href="ntmigration.html#sbent4smb">NT4 Migration Samba-3 Server smb.conf  Part: A</a></dt><dt>9.2. <a href="ntmigration.html#sbent4smb2">NT4 Migration Samba-3 Server smb.conf  Part: B</a></dt><dt>9.3. <a href="ntmigration.html#sbentslapd">NT4 Migration LDAP Server Configuration File: /etc/openldap/slapd.conf  Part A</a></dt><dt>9.4. <a href="ntmigration.html#sbentslapd2">NT4 Migration LDAP Server Configuration File: /etc/openldap/slapd.conf  Part B</a></dt><dt>9.5. <a href="ntmigration.html#sbrntldapconf">NT4 Migration NSS LDAP File: /etc/ldap.conf</a></dt><dt>9.6. <a href="ntmigration.html#sbentnss">NT4 Migration NSS Control File: /etc/nsswitch.conf (Stage:1)</a></dt><dt>9.7. <a href="ntmigration.html#sbentnss2">NT4 Migration NSS Control File: /etc/nsswitch.conf (Stage:2)</a></dt><dt>10.1. <a href="nw4migration.html#sbeamg">A Rough Tool to Create an LDIF File from the System Account Files</a></dt><dt>10.2. <a href="nw4migration.html#ch8ldap">NSS LDAP Control File  /etc/ldap.conf</a></dt><dt>10.3. <a href="nw4migration.html#sbepu2">The PAM Control File /etc/security/pam_unix2.conf</a></dt><dt>10.4. <a href="nw4migration.html#ch8smbconf">Samba Configuration File  smb.conf Part A</a></dt><dt>10.5. <a href="nw4migration.html#ch8smbconf2">Samba Configuration File  smb.conf Part B</a></dt><dt>10.6. <a href="nw4migration.html#ch8smbconf3">Samba Configuration File  smb.conf Part C</a></dt><dt>10.7. <a href="nw4migration.html#ch8smbconf4">Samba Configuration File  smb.conf Part D</a></dt><dt>10.8. <a href="nw4migration.html#ch8smbconf5">Samba Configuration File  smb.conf Part E</a></dt><dt>10.9. <a href="nw4migration.html#sbersync">Rsync Script</a></dt><dt>10.10. <a href="nw4migration.html#sbexcld">Rsync Files Exclusion List  /root/excludes.txt</a></dt><dt>10.11. <a href="nw4migration.html#ch8ideal">Idealx smbldap-tools Control File  Part A</a></dt><dt>10.12. <a href="nw4migration.html#ch8ideal2">Idealx smbldap-tools Control File  Part B</a></dt><dt>10.13. <a href="nw4migration.html#ch8ideal3">Idealx smbldap-tools Control File  Part C</a></dt><dt>10.14. <a href="nw4migration.html#ch8ideal4">Idealx smbldap-tools Control File  Part D</a></dt><dt>10.15. <a href="nw4migration.html#ch8kix">Kixtart Control File  File: logon.kix</a></dt><dt>10.16. <a href="nw4migration.html#ch8kix2">Kixtart Control File  File: main.kix</a></dt><dt>10.17. <a href="nw4migration.html#ch8kix3">Kixtart Control File  File: setup.kix, Part A</a></dt><dt>10.18. <a href="nw4migration.html#ch8kix3b">Kixtart Control File  File: setup.kix, Part B</a></dt><dt>10.19. <a href="nw4migration.html#ch8kix4">Kixtart Control File  File: acct.kix</a></dt><dt>12.1. <a href="DomApps.html#ch10-krb5conf">Kerberos Configuration  File: /etc/krb5.conf</a></dt><dt>12.2. <a href="DomApps.html#ch10-smbconf">Samba Configuration  File: /etc/samba/smb.conf</a></dt><dt>12.3. <a href="DomApps.html#ch10-etcnsscfg">NSS Configuration File Extract  File: /etc/nsswitch.conf</a></dt><dt>12.4. <a href="DomApps.html#etcsquidcfg">Squid Configuration File Extract  /etc/squid.conf [ADMINISTRATIVE PARAMETERS Section]</a></dt><dt>12.5. <a href="DomApps.html#etcsquid2">Squid Configuration File extract  File: /etc/squid.conf [AUTHENTICATION PARAMETERS Section]</a></dt><dt>15.1. <a href="appendix.html#ch12SL">A Useful Samba Control Script for SUSE Linux</a></dt><dt>15.2. <a href="appendix.html#ch12RHscript">A Sample Samba Control Script for Red Hat Linux</a></dt><dt>15.3. <a href="appendix.html#loopback">DNS Localhost Forward Zone File: /var/lib/named/localhost.zone</a></dt><dt>15.4. <a href="appendix.html#dnsloopy">DNS Localhost Reverse Zone File: /var/lib/named/127.0.0.zone</a></dt><dt>15.5. <a href="appendix.html#roothint">DNS Root Name Server Hint File: /var/lib/named/root.hint</a></dt><dt>15.6. <a href="appendix.html#sbehap-ldapreconfa">LDAP Pre-configuration Script: SMBLDAP-ldif-preconfig.sh  Part A</a></dt><dt>15.7. <a href="appendix.html#sbehap-ldapreconfb">LDAP Pre-configuration Script: SMBLDAP-ldif-preconfig.sh  Part B</a></dt><dt>15.8. <a href="appendix.html#sbehap-ldapreconfc">LDAP Pre-configuration Script: SMBLDAP-ldif-preconfig.sh  Part C</a></dt><dt>15.9. <a href="appendix.html#sbehap-ldifpata">LDIF Pattern File Used to Pre-configure LDAP  Part A</a></dt><dt>15.10. <a href="appendix.html#sbehap-ldifpatb">LDIF Pattern File Used to Pre-configure LDAP  Part B</a></dt><dt>15.11. <a href="appendix.html#lamcfg">Example LAM Configuration File  config.cfg</a></dt><dt>15.12. <a href="appendix.html#lamconf">LAM Profile Control File  lam.conf</a></dt></dl></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"> </td><td width="20%" align="center"> </td><td width="40%" align="right"> <a accesskey="n" href="pr01.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top"> </td><td width="20%" align="center"> </td><td width="40%" align="right" valign="top"> About the Cover Artwork</td></tr></table></div></body></html>
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/ix01.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Index</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="go01.html" title="Glossary"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Index</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> </td></tr></table><hr></div><div class="index"><div class="titlepage"><div><div><h2 class="title"><a name="id2630860"></a>Index</h2></div></div></div><div class="index"><div class="indexdiv"><h3>Symbols</h3><dl><dt>%LOGONSERVER%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>%USERNAME%, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a></dt><dt>%USERPROFILE%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>/data/ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>/etc/cups/mime.convs, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/cups/mime.types, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/dhcpd.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>/etc/exports, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>/etc/group, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/hosts, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>/etc/krb5.conf, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>/etc/ldap.conf, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>/etc/mime.convs, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/mime.types, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/named.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>/etc/nsswitch.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/etc/openldap/slapd.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>/etc/passwd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>/etc/rc.d/boot.local, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>/etc/rc.d/rc.local, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>/etc/resolv.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/etc/samba/secrets.tdb, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>/etc/samba/smbusers, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/shadow, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>/etc/squid/squid.conf, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/syslog.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/etc/xinetd.d, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>/lib/libnss_ldap.so.2, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>/opt/IDEALX/sbin, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/proc/sys/net/ipv4/ip_forward, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>/usr/bin, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/lib/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/local, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/local/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/local/samba/var/locks, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/usr/sbin, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/share, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/share/samba/swat, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/usr/share/swat, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/var/cache/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/var/lib/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>/var/log/ldaplogs, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/var/log/samba, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>8-bit, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt></dl></div><div class="indexdiv"><h3></h3><dl><dt>, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="Big500users.html#id2565659">Implementation</a>, <a class="indexterm" href="happy.html#sbehap-ppc">Addition of Machines to the Domain</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a></dt><dd><dl><dt>Domain account, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>logon, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>problem, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>transparent inter-operability, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></dd></dl></div><div class="indexdiv"><h3>A</h3><dl><dt>abmas-netfw.sh, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>accept, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>accepts liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>access, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>access control, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a>, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>Access Control Lists (see ACLs)</dt><dt>access control settings, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>access controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>accessible, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dd><dl><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>account credentials, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>account information, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>account names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>account policies, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>accountable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>accounts</dt><dd><dl><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>machine, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>manage, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>user, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></dd><dt>ACL, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>ACLs, <a class="indexterm" href="happy.html#id2583229">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>acquisitions, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Act!, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>ACT! database, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>Act!Diag, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>Active Directory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2589319">Assignment Tasks</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>authentication, <a class="indexterm" href="DomApps.html#id2617956">Squid Configuration</a></dt><dt>domain, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>management tools, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>realm, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>Replacement, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>tree, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt></dl></dd><dt>active directory, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>AD printer publishing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>ADAM, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>add group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add machine script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>Add Printer Wizard</dt><dd><dl><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>add user script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add user to group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>adduser, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>adequate precautions, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>administrative installation, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>administrative rights, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>administrator, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>ADMT, <a class="indexterm" href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></dt><dt>ADS, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>affordability, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>alarm, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>algorithm, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>allow trusted domains, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>alternative, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>analysis, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>anonymous connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>Apache Web server, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>appliance mode, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>application server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>application servers, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>application/octet-stream, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>arp, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>assessment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>assistance, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>assumptions, <a class="indexterm" href="HA.html#id2620832">Key Points Learned</a></dt><dt>authconfig, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>authenticate, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>authenticated, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dt>authenticated connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>authentication, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dd><dl><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></dd><dt>authentication process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>authentication protocols, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>authorized location, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>auto-generated SID, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>automatically allocate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>availability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt></dl></div><div class="indexdiv"><h3>B</h3><dl><dt>backends, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Backup, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Backup Domain Controller (see BDC)</dt><dt>bandwidth, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dd><dl><dt>requirements, <a class="indexterm" href="2000users.html#id2584178">User Needs</a></dt></dl></dd><dt>bandwidth calculations, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>BDC, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>benefit, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>best practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bias, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>binary database, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>binary files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>binary package, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>bind interfaces only, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>directed, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>mailslot, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>broadcast messages, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast storms, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>broken, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>broken behavior, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>browse, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>browse master, <a class="indexterm" href="primer.html#id2626005">Findings</a></dt><dt>Browse Master, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browse.dat, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Browser Election Service, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browsing, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dt>budgetted, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug fixes, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug report, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt></dl></div><div class="indexdiv"><h3>C</h3><dl><dt>cache, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt><dt>cache directories, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>caching, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>case-sensitive, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>centralized storage, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>character set, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>check samba daemons, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>check-point, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>check-point controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>Checkpoint Controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>chgrp, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>chkconfig, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>chmod, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>choice, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>chown, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>CIFS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="primer.html#id2626005">Findings</a></dt><dt>cifsfs, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>clean database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>clients per DC, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Clock skew, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>cluster, <a class="indexterm" href="HA.html#id2618932">Introduction</a></dt><dt>clustering, <a class="indexterm" href="HA.html#id2618932">Introduction</a>, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>code maintainer, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>codepage, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>collision rates, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>commercial, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621220">Commercial Support</a></dt><dt>Common Internet File System (see CIFS)</dt><dt>comparison</dt><dd><dl><dt>Active Directory &amp; OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>compat, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>compatible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>compile-time, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>complexities, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>compromise, <a class="indexterm" href="happy.html#id2571190">Introduction</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>computer account, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Computer Management, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>computer name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>condemns, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>conferences, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>configuration files, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>configure.pl, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>connection, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>connectivity, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>consequential risk, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consultant, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>consumer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consumer expects, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>contiguous directory, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>contributions, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>control files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>convmv, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>copy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>corrective action, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>cost, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>cost-benefit, <a class="indexterm" href="nw4migration.html#id2606147">Assignment Tasks</a></dt><dt>country of origin, <a class="indexterm" href="ch14.html#id2621220">Commercial Support</a></dt><dt>Courier-IMAP, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>credential, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>credentials, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>crippled, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>criticism, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Critics, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Cryptographic, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>CUPS, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dd><dl><dt>queue, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt></dl></dd><dt>cupsd, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>customer expected, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>customers, <a class="indexterm" href="ch14.html">Samba Support</a></dt></dl></div><div class="indexdiv"><h3>D</h3><dl><dt>daemon, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>daemon control, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>data</dt><dd><dl><dt>corruption, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>integrity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>data corruption, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a>, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>data integrity, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a>, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>data storage, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>database, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>database applications, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>DB_CONFIG, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>DCE, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>DDNS (see dynamic DNS)</dt><dt>Debian, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>default installation, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>default password, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>default profile, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Default User, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>defective</dt><dd><dl><dt>cables, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>HUBs, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>switches, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt></dl></dd><dt>defects, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defensible standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defragmentation, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a></dt><dt>delete group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delete user from group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delimiter, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>dependability, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>deployment, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>desired security setting, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>development, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DHCP, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dd><dl><dt>client, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>relay, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>Relay Agent, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>request, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>requests, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>servers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>traffic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>dhcp client validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>DHCP Server, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>DHCP server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>diagnostic, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>diffusion, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital rights, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital sign'n'seal, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digits, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>diligence, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>directory, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dd><dl><dt>Computers container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>People container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>replication, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>schema, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>server, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>synchronization, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>directory tree, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>disable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disaster recovery, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disk image, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>disruptive, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>distributed, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620470">Distribute Network Load with MSDFS</a></dt><dt>distributed domain, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>DMB, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>DMS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>DNS, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>configuration, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Dynamic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>dynamic, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>name lookup, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>SRV records, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>suffix, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></dd><dt>DNS server, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>document the settings, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>documentation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>documented, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>Domain, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt></dl></dd><dt>domain</dt><dd><dl><dt>Active Directory, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>controller, <a class="indexterm" href="upgrades.html#id2600964">Replacing a Domain Controller</a></dt><dt>joining, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>trusted, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>Domain accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Administrator, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Domain Controller, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dd><dl><dt>closest, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>domain controller, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>domain controllers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Controllers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Domain Groups</dt><dd><dl><dt>well-known, <a class="indexterm" href="appendix.html#id2622954">Initialization of the LDAP Database</a></dt></dl></dd><dt>Domain join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>domain master, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>Domain Master Browser (see DMB)</dt><dt>Domain Member, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dd><dl><dt>authoritative</dt><dd><dl><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>client, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>workstations, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt></dl></dd><dt>domain member</dt><dd><dl><dt>servers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>Domain Member server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Domain Member servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain members, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain name space, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>domain replication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>domain SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Domain SID, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>domain tree, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Domain User Manager, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Domain users, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DOS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>dos2unix, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>down-grade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>drive letters, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>drive mapping, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>dumb printing, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>dump, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>duplicate accounts, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>dynamic DNS, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>E</h3><dl><dt>e-Directory, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Easy Software Products, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>economically sustainable, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>eDirectory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>education, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>election, <a class="indexterm" href="primer.html#id2626005">Findings</a></dt><dt>employment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>enable, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>encrypted, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>encrypted password, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>encrypted passwords, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>End User License Agreement (see EULA)</dt><dt>enumerating, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>essential, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>ethereal, <a class="indexterm" href="primer.html#id2625745">Exercises</a></dt><dt>Ethernet switch, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dt>ethernet switch, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>EULA, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>Everyone, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Excel, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>exclusive open, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt><dt>experiment, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>export, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>extent, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>External Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>extreme demand, <a class="indexterm" href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></dt></dl></div><div class="indexdiv"><h3>F</h3><dl><dt>fail, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>failed, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>failed join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>failure, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>familiar, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fatal problem, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>fear, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fears, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Fedora, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a></dt><dt>FHS, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>file and print server, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>file and print service, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>file caching, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt><dt>File Hierarchy System (see FHS)</dt><dt>file locations, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>file permissions, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>file server</dt><dd><dl><dt>read-only, <a class="indexterm" href="simple.html#id2551026">Dissection and Discussion</a></dt></dl></dd><dt>file servers, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a></dt><dt>file system, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>access control, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>Ext3, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>permissions, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>file system security, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>filter, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>financial responsibility, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>firewall, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>fix, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>flaws, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>flexibility, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>flush</dt><dd><dl><dt>cache memory, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt></dl></dd><dt>folder redirection, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>force group, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>force user, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>forced settings, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>foreign, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>foreign SID, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>forwarded, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>foundation members, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Free Standards Group (see FSG)</dt><dt>free support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>front-end, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dd><dl><dt>server, <a class="indexterm" href="HA.html#id2620470">Distribute Network Load with MSDFS</a></dt></dl></dd><dt>frustration, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>FSG, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>FTP</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></dd><dt>full control, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615018">Using MS Windows Explorer (File Manager)</a></dt><dt>fully qualified, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>functional differences, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt></dl></div><div class="indexdiv"><h3>G</h3><dl><dt>generation, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>Gentoo, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>getent, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>getfacl, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>getgrnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>getpwnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>getpwnam(), <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>GID, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Goettingen, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>government, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>GPL, <a class="indexterm" href="secure.html#id2564111">Comments Regarding Software Terms of Use</a></dt><dt>group account, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>group management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>group mapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>group membership, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>group names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group policies, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a></dt><dt>Group Policy, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>Group Policy editor, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>Group Policy Objects, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>groupadd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupmem, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>groupmod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>GSS-API, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>guest account, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a>, <a class="indexterm" href="primer.html#chap01conc">Dissection and Discussion</a>, <a class="indexterm" href="primer.html#id2628204">Technical Issues</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>H</h3><dl><dt>hackers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>hardware prices, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>hardware problems, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>Heimdal, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Heimdal Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Heimdal kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>help, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>helper agent, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>hesiod, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>hierarchy of control, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>high availability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>hire, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>HKEY_CURRENT_USER, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>HKEY_LOCAL_MACHINE, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>HKEY_LOCAL_USER, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>host announcement, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a>, <a class="indexterm" href="primer.html#id2626658">Findings</a></dt><dt>hostname, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>hosts, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>HUB, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Hybrid, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>hypothetical, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>I</h3><dl><dt>Idealx, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dd><dl><dt>smbldap-tools, <a class="indexterm" href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt></dl></dd><dt>identifiers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>identity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>management, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt></dl></dd><dt>identity management, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Identity Management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Identity management, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>Identity resolution, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Identity resolver, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>IDMAP, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap backend, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>IDMAP backend, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>idmap gid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap uid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap_rid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>IMAP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>import, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>income, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>independent expert, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>inetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>inetOrgPerson, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>inheritance, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>initGrps.sh, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>initial credentials, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>inoperative, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>install, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>installation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>integrate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>integrity, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>inter-domain, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>inter-operability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>interactive help, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>interdomain trusts, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>interfaces, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>intermittent, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>internationalization, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Internet Explorer, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>Internet Information Server, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>interoperability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>IP forwarding, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>IPC$, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>iptables, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>IRC, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>isolated, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Italian, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>J</h3><dl><dt>jobs, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>joining a domain, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></div><div class="indexdiv"><h3>K</h3><dl><dt>KDC, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dd><dl><dt>Heimdal, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>interoperability, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>libraries, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>MIT, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>unspecified fields, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>kerberos, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>Kerberos ticket, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>kinit, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>Kixtart, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>klist, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>krb5, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a></dt><dt>krb5.conf, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt></dl></div><div class="indexdiv"><h3>L</h3><dl><dt>LAM, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dd><dl><dt>configuration editor, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>configuration file, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>login screen, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>opening screen, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>profile, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>wizard, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt></dl></dd><dt>large domain, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>LDAP, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2573037">Preliminary Advice: Dangers Can Be Avoided</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2583767">Introduction</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>backend, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>database, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>directory, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>initial configuration, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>master/slave</dt><dd><dl><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>preload, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>schema, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>secure, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>updates, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>ldap, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>LDAP Account Manager (see LAM)</dt><dt>LDAP backend, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>LDAP database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>LDAP Interchange Format (see LDIF)</dt><dt>LDAP server, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>LDAP-transfer-LDIF.txt, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>ldap.conf, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>ldapadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>ldapsam, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>ldapsam backend, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>ldapsearch, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>LDIF, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2622954">Initialization of the LDAP Database</a></dt><dt>leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Lightweight Directory Access Protocol (see LDAP)</dt><dt>limit, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Linux desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>Linux Standards Base (see LSB)</dt><dt>LMB, <a class="indexterm" href="primer.html#id2626005">Findings</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>LMHOSTS, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>load distribution, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Local Group Policy, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>Local Master Announcement, <a class="indexterm" href="primer.html#id2626658">Findings</a></dt><dt>Local Master Browser (see LMB)</dt><dt>localhost, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>lock directory, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>locking</dt><dd><dl><dt>Application level, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Client side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Server side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>logging, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>login, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>loglevel, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>logon credentials, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>logon hours, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a></dt><dt>logon machines, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon path, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>logon scrip, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>logon script, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2581163">Preparation of Logon Scripts</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon server, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon services, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon time, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>logon traffic, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon.kix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>loopback, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>low performance, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>lower-case, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>lpadmin, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>LSB, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>M</h3><dl><dt>machine, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>machine account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>machine accounts, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>machine secret password, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>MACHINE.SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>mailing list, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>mailing lists, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>managed, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>management, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dd><dl><dt>group, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>User, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>mandatory profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Mandrake, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>mapped drives, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>mapping, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dd><dl><dt>consistent, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt></dl></dd><dt>Mars_NWE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>material, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>memberUID, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>memory requirements, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>merge, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>merged, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>meta-directory, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>meta-service, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Microsoft Access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft Excel, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft ISA, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dt>Microsoft Management Console (see MMC)</dt><dt>Microsoft Office, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>Microsoft Outlook</dt><dd><dl><dt>PST files, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>migrate, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>migration, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dd><dl><dt>objectives, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd><dt>Migration speed, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mime type, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>mime types, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>missing RPC's, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>MIT, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>MIT Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>MIT kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>MIT KRB5, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>mixed mode, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>mixed-mode, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>MMC, <a class="indexterm" href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>mobile computing, <a class="indexterm" href="small.html#id2555545">Dissection and Discussion</a></dt><dt>mobility, <a class="indexterm" href="2000users.html#id2584139">Technical Issues</a></dt><dt>modularization, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>modules, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>MS Access</dt><dd><dl><dt>validate, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt></dl></dd><dt>MS Outlook, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>PST file, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>MS Windows Server 2003, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a></dt><dt>MS Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>MSDFS, <a class="indexterm" href="HA.html#id2620470">Distribute Network Load with MSDFS</a></dt><dt>multi-subnet, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>multi-user</dt><dd><dl><dt>access, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt><dt>data access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>multiple directories, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>multiple domain controllers, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>multiple group mappings, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mutual assistance, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>My Documents, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>My Network Places, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>mysqlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>N</h3><dl><dt>name resolution, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dd><dl><dt>Defective, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>name resolve order, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>name service switch, <a class="indexterm" href="small.html#id2555812">Implementation</a> (see NSS)</dt><dt>named, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>NAT, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>native, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>net</dt><dd><dl><dt>ads</dt><dd><dl><dt>info, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>status, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>getlocalsid, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>groupmap</dt><dd><dl><dt>add, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>list, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>modify, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt></dl></dd><dt>rpc</dt><dd><dl><dt>info, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>join, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>vampire, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt></dl></dd><dt>setlocalsid, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>NetBIOS, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>name cache, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>name resolution</dt><dd><dl><dt>delays, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Node Type, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></dd><dt>netbios</dt><dd><dl><dt>machine  name, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a></dt></dl></dd><dt>netbios forwarding, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>NetBIOS name, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dd><dl><dt>aliases, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>netbios name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>NETLOGON, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="happy.html#id2581407">Windows Client Configuration</a></dt><dt>netlogon, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Netlogon, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>netmask, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>Netware, <a class="indexterm" href="small.html">Small Office Networking</a></dt><dt>NetWare, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>network</dt><dd><dl><dt>administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>analyzer, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dt>bandwidth, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>broadcast, <a class="indexterm" href="primer.html#id2625568">Introduction</a></dt><dt>captures, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>collisions, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>load, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>logon scripts, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>management, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>multi-segment, <a class="indexterm" href="happy.html#id2571190">Introduction</a></dt><dt>overload, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>performance, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>routed, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>segment, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>sniffer, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>timeout, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>timeouts, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>trace, <a class="indexterm" href="primer.html#id2625629">Assignment Tasks</a></dt><dt>traffic</dt><dd><dl><dt>observation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>wide-area, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt></dl></dd><dt>Network Address Translation (see NAT)</dt><dt>network administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network attached storage (see NAS)</dt><dt>network bandwidth</dt><dd><dl><dt>utilization, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Network Default Profile, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>network hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>network hygiene, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>network Identities, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>network load factors, <a class="indexterm" href="Big500users.html#id2565398">Dissection and Discussion</a></dt><dt>Network Neighborhood, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network segment, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>network segments, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>network share, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>networking</dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>networking hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>next generation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>NextFreeUnixId, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NFS server, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>NICs, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>NIS, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>nis, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>NIS schema, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS server, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS+, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>nisplus, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>NLM, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>nmap, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>nmbd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>nobody, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>Novell, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>Novell SUSE SLES 9, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NSS, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a> (see same service switch)</dt><dt>nss_ldap, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>nt acl support, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>NT4 registry, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>NTLM, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>NTLM authentication daemon, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>NTLMSSP, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>NTLMSSP_AUTH, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>ntlm_auth, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>NTP, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>NTUSER.DAT, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NULL connection, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>NULL session, <a class="indexterm" href="primer.html#id2627256">Findings and Comments</a></dt><dt>NULL-Session, <a class="indexterm" href="primer.html#id2628058">Discussion</a></dt></dl></div><div class="indexdiv"><h3>O</h3><dl><dt>objectClass, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>off-site storage, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Open Magazine, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>Open Source, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>openldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>OpenOffice, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>operating profiles, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>oplock break, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>oplocks, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>Oplocks</dt><dd><dl><dt>disabled, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt></dl></dd><dt>opportunistic</dt><dd><dl><dt>locking, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt></dl></dd><dt>opportunistic locking, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625156">Act! Database Sharing</a></dt><dt>optimized, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>organizational units, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>OS/2, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Outlook</dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt></dl></dd><dt>Outlook Address Book, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>Outlook Express, <a class="indexterm" href="secure.html#id2559309">Political Issues</a>, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>over-ride, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>over-ride controls, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>over-rule, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615018">Using MS Windows Explorer (File Manager)</a></dt><dt>overheads, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>ownership, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></div><div class="indexdiv"><h3>P</h3><dl><dt>package, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>package names, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>packages, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>PADL, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>PADL LDAP tools, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>PADL Software, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>paid-for support, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>PAM, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>pam_ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>pam_ldap.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>pam_unix2.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dd><dl><dt>use_ldap, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt></dl></dd><dt>parameters, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>passdb backend, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>passdb.tdb, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>passwd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>password</dt><dd><dl><dt>backend, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>password caching, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>password change, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a></dt><dt>password length, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>payroll, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>pdbedit, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>PDC, <a class="indexterm" href="Big500users.html#id2565292">Assignment Tasks</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>PDC/BDC ratio, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>PDF, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>performance, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a>, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a>, <a class="indexterm" href="HA.html#id2618932">Introduction</a>, <a class="indexterm" href="HA.html#id2619896">Network Collisions</a></dt><dt>performance degradation, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>Perl, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>permission, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>permissions, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>excessive, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>group, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>user, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></dd><dt>Permissions, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>permits, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>permitted group, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>PHP, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>PHP4, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>pile-driver, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>ping, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>pitfalls, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>Pluggable Authentication Modules (see PAM)</dt><dt>policy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>poor performance, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>POP3, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>Posix, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>POSIX, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Posix accounts, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Posix ACLs, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>PosixAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>posixAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postfix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postscript, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>powers, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>precaution, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>presence and leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>price paid, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>primary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>principals, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>print filter, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>print queue, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>print spooler, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a></dt><dt>Print Test Page, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>printcap name, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>printer validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>printers</dt><dd><dl><dt>Advanced, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Default Settings, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>General, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Properties, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Security, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Sharing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>printing, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dd><dl><dt>drag-and-drop, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>dumb, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>point-n-click, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt></dl></dd><dt>privacy, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Privilege Attribute Certificates (see PAC)</dt><dt>privilege controls, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>privileged pipe, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>privileges, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>problem report, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>problem resolution, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>product defects, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>professional support, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>profile</dt><dd><dl><dt>default, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>mandatory, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>roaming, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>profile path, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>profile share, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>profiles, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>profiles share, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>programmer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>project, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>project maintainers, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Properties, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>proprietary, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protected, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protection, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protocol</dt><dd><dl><dt>negotiation, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>protocol analysis, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>provided services, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>proxy, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>PST file, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>public specifications, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>purchase support, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt></dl></div><div class="indexdiv"><h3>Q</h3><dl><dt>Qbasic, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>qualified problem, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt></dl></div><div class="indexdiv"><h3>R</h3><dl><dt>RAID, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>RAID controllers, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>Raw Print Through, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw printing, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>Rbase, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>rcldap, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>realm, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>recognize, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>record locking, <a class="indexterm" href="appendix.html#id2625009">Microsoft Access</a></dt><dt>recursively, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Red Hat, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>Red Hat Fedora Linux, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Red Hat Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="simple.html#AccountingOffice">Accounting Office</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>redirected folders, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>refereed standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>regedit, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>regedt32, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dd><dl><dt>keys</dt><dd><dl><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>SECURITY, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd></dl></dd><dt>registry change, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Registry Editor, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry hacks, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>registry keys, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>reimburse, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>rejected, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>rejoin, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>reliability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt><dt>remote announce, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>remote browse sync, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>remote procedure call (see RPC)</dt><dt>replicate, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>replicated, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>requesting payment, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>resilient, <a class="indexterm" href="HA.html#id2619492">Guidelines for Reliable Samba Operation</a></dt><dt>resolution, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>resolve, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="HA.html#id2619531">Bad Hostnames</a></dt><dt>response, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>responsibility, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>responsible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>restrict anonymous, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>restricted export, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Restrictive security, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>reverse DNS, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a></dt><dt>rfc2307bis, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a></dt><dt>RID, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>risk, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>road-map, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>published, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>roaming profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>roaming profiles, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>routed network, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a></dt><dt>router, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>routers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>RPC, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>rpc, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>rpcclient, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>RPM, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dd><dl><dt>install, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>rpm, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>RPMs, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>rpms, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>rsync, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>rsyncd.conf, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>run-time control files, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>S</h3><dl><dt>safe-guards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>samba, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>Samba, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Samba accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>samba cluster, <a class="indexterm" href="HA.html#id2618932">Introduction</a></dt><dt>samba control script, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>Samba Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Samba Domain server, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>Samba RPM Packages, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>Samba Tea, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>sambaDomainName, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>sambaGroupMapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaSAMAccount, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>SambaSamAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>sambaSamAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaXP conference, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>SAN, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>SAS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>scalability, <a class="indexterm" href="HA.html#id2618932">Introduction</a></dt><dt>scalable, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>schannel, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>schema, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>scripts, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>secondary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>secret, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>secrets.tdb, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>secure account password, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>secure connections, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>secure networking, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>secure networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dd><dl><dt>identifier, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>share mode, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>user mode, <a class="indexterm" href="simple.html#id2553821">Dissection and Discussion</a></dt></dl></dd><dt>Security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614727">Using the MMC Computer Management Interface</a></dt><dt>Security Account Manager (see SAM)</dt><dt>security controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security descriptors, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>security fixes, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security updates, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SerNet, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>server</dt><dd><dl><dt>domain member, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>stand-alone, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>service, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dd><dl><dt>smb</dt><dd><dl><dt>start, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a></dt></dl></dd></dl></dd><dt>Service Packs, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt><dt>services provided, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>session setup, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>Session Setup, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></dt><dt>SessionSetUpAndX, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>set primary group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>setfacl, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>severely degrade, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>SFU, <a class="indexterm" href="unixclients.html#id2596287">IDMAP, Active Directory, and MS Services for UNIX 3.5</a></dt><dt>SGID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>shadow-utils, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Share Access Controls, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>share ACLs, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>share definition, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Share Definition</dt><dd><dl><dt>Controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt></dl></dd><dt>share definition controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>share level access controls, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>share level ACL, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Share Permissions, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>shared resource, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>shares, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SID, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622954">Initialization of the LDAP Database</a></dt><dt>side effects, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>Sign'n'seal, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>silent return, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>simple, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>Single Sign-On (see SSO)</dt><dt>slapcat, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>slapd, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>slapd.conf, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>slow logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>slow network, <a class="indexterm" href="HA.html#id2620570">Hardware Problems</a></dt><dt>slurpd, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>smart printing, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>SMB, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>SMB passwords, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>SMB/CIFS, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>smbclient, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>smbd, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dd><dl><dt>location of files, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt></dl></dd><dt>smbfs, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbldap-groupadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-groupmod, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-passwd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-populate, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>smbldap-tools updating, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>smbldap-useradd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>smbldap-usermod, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbmnt, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbmount, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbpasswd, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>smbumnt, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>smbumount, <a class="indexterm" href="HA.html#id2619019">Dissection and Discussion</a></dt><dt>SMTP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>snap-shot, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>socket address, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>socket options, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>solve, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>source code, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>SPNEGO, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>SQL, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Squid, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617956">Squid Configuration</a></dt><dt>squid, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>Squid proxy, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>SRVTOOLS.EXE, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>SSL, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>stand-alone server, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>starting CUPS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting dhcpd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dd><dl><dt>nmbd, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>smbd, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>winbindd, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt></dl></dd><dt>startingCUPS, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>startup script, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>sticky bit, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>storage capacity, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>strategic, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>strategy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>straw-man, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>strict sync, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>stripped, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>strong cryptography, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>subscription, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>SUID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>Sun ONE Identity Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>super daemon, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>support, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>survey, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>SUSE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>SUSE Enterprise Linux Server, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a></dt><dt>SUSE Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616500">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>SWAT, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>sync always, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>synchronization, <a class="indexterm" href="DomApps.html#id2616749">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2620420">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>synchronize, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>synchronized, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>syslog, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>system level logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>system security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>T</h3><dl><dt>tattooing, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>TCP/IP, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>tdbdump, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>tdbsam, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>testparm, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="HA.html#id2619995">Samba Configuration</a></dt><dt>ticket, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>time server, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>Tivoli Directory Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>TLS, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>token, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a></dt><dt>tool, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>TOSHARG2, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>track record, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>traffic collisions, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>transaction processing, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>transactional, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>transfer, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>translate, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>traverse, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>tree, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Tree Connect, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></dt><dt>trust account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>trusted computing, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Trusted Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>trusted domains, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>trusted third-party, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>trusting, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>turn-around time, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>U</h3><dl><dt>UDP</dt><dd><dl><dt>broadcast, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt></dl></dd><dt>UID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>un-join, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>unauthorized activities, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>UNC name, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>unencrypted, <a class="indexterm" href="appendix.html#id2623532">The LDAP Account Manager</a></dt><dt>Unicast, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>unicode, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Universal Naming Convention (see UNC name)</dt><dt>UNIX, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt></dl></dd><dt>UNIX accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>UNIX/Linux server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unix2dos, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>unknown, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unsupported software, <a class="indexterm" href="ch14.html#id2621220">Commercial Support</a></dt><dt>update, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>updates, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>updating smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>upgrade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>uppercase, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>user</dt><dd><dl><dt>management, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>user account, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>User and Group Controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>user credentials, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>user errors, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user groups, <a class="indexterm" href="ch14.html#id2621002">Free Support</a></dt><dt>user identities, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>user logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>User Manager, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>User Mode, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>useradd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>userdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>usermod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>username, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>username map, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>UTF-8, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>utilities, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>V</h3><dl><dt>valid users, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>validate, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>validated, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>validation, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>vampire, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>vendor, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>vendors, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>VFS modules, <a class="indexterm" href="appendix.html#id2621928">Samba System File Location</a></dt><dt>virus, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>VPN, <a class="indexterm" href="2000users.html#id2583797">Assignment Tasks</a></dt><dt>vulnerabilities, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>W</h3><dl><dt>wbinfo, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a></dt><dt>weakness, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>web</dt><dd><dl><dt>caching, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt><dt>proxying, <a class="indexterm" href="DomApps.html#id2616193">Assignment Tasks</a></dt></dl></dd><dt>Web</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dd><dl><dt>access, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt></dl></dd></dl></dd><dt>Web browsers, <a class="indexterm" href="DomApps.html#id2618352">Key Points Learned</a></dt><dt>WebClient, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>WHATSNEW.txt, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></dt><dt>white-pages, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>wide-area, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>wide-area network, <a class="indexterm" href="HA.html#id2620323">Use and Location of BDCs</a>, <a class="indexterm" href="HA.html#id2620524">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>winbind, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589354">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616327">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617691">NSS Configuration</a></dt><dt>Winbind, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615399">Key Points Learned</a></dt><dt>winbind trusted domains only, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>winbind use default domain, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>winbindd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617139">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622349">Starting Samba</a></dt><dt>winbindd_cache.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>winbindd_idmap.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Windows, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>NT, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>Windows 2000 ACLs, <a class="indexterm" href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></dt><dt>Windows 2003 Serve, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows 200x ACLs, <a class="indexterm" href="kerberos.html#id2615533">Questions and Answers</a></dt><dt>Windows accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Windows ACLs, <a class="indexterm" href="kerberos.html#id2615189">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Windows Address Book, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Windows ADS Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>Windows clients, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>Windows Explorer, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>Windows explorer, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>Windows security identifier (see SID)</dt><dt>Windows Servers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows Services for UNIX (see SUS)</dt><dt>Windows XP, <a class="indexterm" href="small.html#id2555484">Assignment Tasks</a></dt><dt>WINS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>name resolution, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt><dt>server, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="HA.html#id2619723">Routed Networks</a></dt></dl></dd><dt>WINS server, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>WINS serving, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins support, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins.dat, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Wireshark, <a class="indexterm" href="primer.html#id2625407">Requirements and Notes</a></dt><dt>wireshark, <a class="indexterm" href="primer.html#id2625745">Exercises</a></dt><dt>Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>workgroup, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a></dt><dt>Workgroup Announcement, <a class="indexterm" href="primer.html#id2626658">Findings</a></dt><dt>workstation, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>wrapper, <a class="indexterm" href="DomApps.html#id2618413">Questions and Answers</a></dt><dt>write lock, <a class="indexterm" href="appendix.html#id2625241">Opportunistic Locking Controls</a></dt></dl></div><div class="indexdiv"><h3>X</h3><dl><dt>xinetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>XML, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>xmlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>Y</h3><dl><dt>YaST, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>Yellow Pages, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>yellow pages (see NIS)</dt></dl></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><td width="20%" align="center"> </td><td width="40%" align="right"> </td></tr><tr><td width="40%" align="left" valign="top">Glossary </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> </td></tr></table></div></body></html>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Index</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="index.html" title="Samba-3 by Example"><link rel="prev" href="go01.html" title="Glossary"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Index</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><th width="60%" align="center"> </th><td width="20%" align="right"> </td></tr></table><hr></div><div class="index"><div class="titlepage"><div><div><h2 class="title"><a name="id2630895"></a>Index</h2></div></div></div><div class="index"><div class="indexdiv"><h3>Symbols</h3><dl><dt>%LOGONSERVER%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>%USERNAME%, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a></dt><dt>%USERPROFILE%, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>/data/ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>/etc/cups/mime.convs, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/cups/mime.types, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>/etc/dhcpd.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>/etc/exports, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>/etc/group, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/hosts, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>/etc/krb5.conf, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>/etc/ldap.conf, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>/etc/mime.convs, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/mime.types, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>/etc/named.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>/etc/nsswitch.conf, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/etc/openldap/slapd.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>/etc/passwd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>/etc/rc.d/boot.local, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>/etc/rc.d/rc.local, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>/etc/resolv.conf, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/etc/samba/secrets.tdb, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>/etc/samba/smbusers, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>/etc/shadow, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>/etc/squid/squid.conf, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>/etc/syslog.conf, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/etc/xinetd.d, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>/lib/libnss_ldap.so.2, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>/opt/IDEALX/sbin, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>/proc/sys/net/ipv4/ip_forward, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>/usr/bin, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/lib/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/local, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/local/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/local/samba/var/locks, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/usr/sbin, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/share, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/share/samba/swat, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/usr/share/swat, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/var/cache/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>/var/lib/samba, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>/var/log/ldaplogs, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>/var/log/samba, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>8-bit, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt></dl></div><div class="indexdiv"><h3></h3><dl><dt>, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="Big500users.html#id2565659">Implementation</a>, <a class="indexterm" href="happy.html#sbehap-ppc">Addition of Machines to the Domain</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a></dt><dd><dl><dt>Domain account, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>logon, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>problem, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>transparent inter-operability, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></dd></dl></div><div class="indexdiv"><h3>A</h3><dl><dt>abmas-netfw.sh, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>accept, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>accepts liability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>access, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>access control, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a>, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>Access Control Lists (see ACLs)</dt><dt>access control settings, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>access controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>accessible, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dd><dl><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>account credentials, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>account information, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>account names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>account policies, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>accountable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>accounts</dt><dd><dl><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>machine, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>manage, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>user, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></dd><dt>ACL, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>ACLs, <a class="indexterm" href="happy.html#id2583229">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>acquisitions, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Act!, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>ACT! database, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>Act!Diag, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>Active Directory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2589319">Assignment Tasks</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>authentication, <a class="indexterm" href="DomApps.html#id2617976">Squid Configuration</a></dt><dt>domain, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>management tools, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>realm, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>Replacement, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>tree, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt></dl></dd><dt>active directory, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>AD printer publishing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>ADAM, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>add group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add machine script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>Add Printer Wizard</dt><dd><dl><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>add user script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>add user to group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>adduser, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>adequate precautions, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>administrative installation, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>administrative rights, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>administrator, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>ADMT, <a class="indexterm" href="upgrades.html#id2601164">Migration of Samba Accounts to Active Directory</a></dt><dt>ADS, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>ADS Domain, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>affordability, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>alarm, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>algorithm, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>allow trusted domains, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>alternative, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>analysis, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>anonymous connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>Apache Web server, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>appliance mode, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>application server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>application servers, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>application/octet-stream, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>APW, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>arp, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>assessment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>assistance, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>assumptions, <a class="indexterm" href="HA.html#id2620859">Key Points Learned</a></dt><dt>authconfig, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>authenticate, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>authenticated, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dt>authenticated connection, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>authentication, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dd><dl><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></dd><dt>authentication process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>authentication protocols, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt><dt>authoritative, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>authorized location, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>auto-generated SID, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>automatically allocate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>availability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt></dl></div><div class="indexdiv"><h3>B</h3><dl><dt>backends, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Backup, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Backup Domain Controller (see BDC)</dt><dt>bandwidth, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dd><dl><dt>requirements, <a class="indexterm" href="2000users.html#id2584178">User Needs</a></dt></dl></dd><dt>bandwidth calculations, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>BDC, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>benefit, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>best practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bias, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>binary database, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>binary files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>binary package, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>bind interfaces only, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>directed, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>mailslot, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>broadcast messages, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>broadcast storms, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>broken, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>broken behavior, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>browse, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>browse master, <a class="indexterm" href="primer.html#id2626028">Findings</a></dt><dt>Browse Master, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browse.dat, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Browser Election Service, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>browsing, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dt>budgetted, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug fixes, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>bug report, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt></dl></div><div class="indexdiv"><h3>C</h3><dl><dt>cache, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt><dt>cache directories, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>caching, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>case-sensitive, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>centralized storage, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>character set, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>check samba daemons, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>check-point, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>check-point controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>Checkpoint Controls, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>chgrp, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>chkconfig, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>chmod, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>choice, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>chown, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>CIFS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="primer.html#id2626028">Findings</a></dt><dt>cifsfs, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>clean database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>clients per DC, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Clock skew, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>cluster, <a class="indexterm" href="HA.html#id2618959">Introduction</a></dt><dt>clustering, <a class="indexterm" href="HA.html#id2618959">Introduction</a>, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>code maintainer, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>codepage, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>collision rates, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>commercial, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>commercial support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621247">Commercial Support</a></dt><dt>Common Internet File System (see CIFS)</dt><dt>comparison</dt><dd><dl><dt>Active Directory &amp; OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>compat, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>compatible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>compile-time, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>complexities, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>compromise, <a class="indexterm" href="happy.html#id2571190">Introduction</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>computer account, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Computer Management, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>computer name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>condemns, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>conferences, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>configuration files, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>configure.pl, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>connection, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>connectivity, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>consequential risk, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consultant, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>consumer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>consumer expects, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>contiguous directory, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>contributions, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>control files, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>convmv, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>copy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>corrective action, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>cost, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>cost-benefit, <a class="indexterm" href="nw4migration.html#id2606147">Assignment Tasks</a></dt><dt>country of origin, <a class="indexterm" href="ch14.html#id2621247">Commercial Support</a></dt><dt>Courier-IMAP, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>credential, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>credentials, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>crippled, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>criticism, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Critics, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Cryptographic, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>CUPS, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dd><dl><dt>queue, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt></dl></dd><dt>cupsd, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a></dt><dt>customer expected, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>customers, <a class="indexterm" href="ch14.html">Samba Support</a></dt></dl></div><div class="indexdiv"><h3>D</h3><dl><dt>daemon, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>daemon control, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>data</dt><dd><dl><dt>corruption, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>integrity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>data corruption, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a>, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>data integrity, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a>, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>data storage, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>database, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>database applications, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>DB_CONFIG, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>DCE, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>DDNS (see dynamic DNS)</dt><dt>Debian, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>default installation, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>default password, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>default profile, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Default User, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>defective</dt><dd><dl><dt>cables, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>HUBs, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>switches, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt></dl></dd><dt>defects, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defensible standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>defragmentation, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a></dt><dt>delete group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delete user from group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>delimiter, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>dependability, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>deployment, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>desired security setting, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>development, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DHCP, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dd><dl><dt>client, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>relay, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>Relay Agent, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>request, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>requests, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>servers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>traffic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>dhcp client validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>DHCP Server, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>DHCP server, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>diagnostic, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>diffusion, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital rights, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digital sign'n'seal, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>digits, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>diligence, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>directory, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dd><dl><dt>Computers container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>People container, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>replication, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>schema, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>server, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>synchronization, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt></dl></dd><dt>directory tree, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>disable, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disaster recovery, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>disk image, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>disruptive, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>distributed, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620507">Distribute Network Load with MSDFS</a></dt><dt>distributed domain, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>DMB, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>DMS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>DNS, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a>, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dd><dl><dt>configuration, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Dynamic, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>dynamic, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>name lookup, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>SRV records, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>suffix, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></dd><dt>DNS server, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a></dt><dt>document the settings, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>documentation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>documented, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>Domain, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt></dl></dd><dt>domain</dt><dd><dl><dt>Active Directory, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>controller, <a class="indexterm" href="upgrades.html#id2600964">Replacing a Domain Controller</a></dt><dt>joining, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>trusted, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt></dl></dd><dt>Domain accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Administrator, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Domain Controller, <a class="indexterm" href="small.html#id2558030">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dd><dl><dt>closest, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>domain controller, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>domain controllers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Domain Controllers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Domain Groups</dt><dd><dl><dt>well-known, <a class="indexterm" href="appendix.html#id2622975">Initialization of the LDAP Database</a></dt></dl></dd><dt>Domain join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>domain master, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>Domain Master Browser (see DMB)</dt><dt>Domain Member, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dd><dl><dt>authoritative</dt><dd><dl><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>client, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>workstations, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt></dl></dd><dt>domain member</dt><dd><dl><dt>servers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt></dl></dd><dt>Domain Member server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Domain Member servers, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain members, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>domain name space, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>domain replication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>domain SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Domain SID, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>domain tree, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Domain User Manager, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Domain users, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>DOS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>dos2unix, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>down-grade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>drive letters, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>drive mapping, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>dumb printing, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>dump, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>duplicate accounts, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>dynamic DNS, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>E</h3><dl><dt>e-Directory, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Easy Software Products, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>economically sustainable, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>eDirectory, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>education, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>election, <a class="indexterm" href="primer.html#id2626028">Findings</a></dt><dt>employment, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>enable, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a></dt><dt>encrypted, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>encrypted password, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>encrypted passwords, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>End User License Agreement (see EULA)</dt><dt>enumerating, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>essential, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>ethereal, <a class="indexterm" href="primer.html#id2625769">Exercises</a></dt><dt>Ethernet switch, <a class="indexterm" href="small.html#id2555593">Technical Issues</a></dt><dt>ethernet switch, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>EULA, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>Everyone, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>Excel, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>exclusive open, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt><dt>experiment, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>export, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>extent, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>External Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>extreme demand, <a class="indexterm" href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></dt></dl></div><div class="indexdiv"><h3>F</h3><dl><dt>fail, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>failed, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>failed join, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>failure, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>familiar, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fatal problem, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>fear, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>fears, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Fedora, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a></dt><dt>FHS, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>file and print server, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>file and print service, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>file caching, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt><dt>File Hierarchy System (see FHS)</dt><dt>file locations, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>file permissions, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>file server</dt><dd><dl><dt>read-only, <a class="indexterm" href="simple.html#id2551026">Dissection and Discussion</a></dt></dl></dd><dt>file servers, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a></dt><dt>file system, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>access control, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>Ext3, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>permissions, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>file system security, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>filter, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>financial responsibility, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>firewall, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>fix, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>flaws, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>flexibility, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>flush</dt><dd><dl><dt>cache memory, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt></dl></dd><dt>folder redirection, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>force group, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>force user, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>forced settings, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>foreign, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>foreign SID, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>forwarded, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>foundation members, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Free Standards Group (see FSG)</dt><dt>free support, <a class="indexterm" href="ch14.html">Samba Support</a>, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>front-end, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dd><dl><dt>server, <a class="indexterm" href="HA.html#id2620507">Distribute Network Load with MSDFS</a></dt></dl></dd><dt>frustration, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>FSG, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>FTP</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></dd><dt>full control, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615027">Using MS Windows Explorer (File Manager)</a></dt><dt>fully qualified, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>functional differences, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt></dl></div><div class="indexdiv"><h3>G</h3><dl><dt>generation, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>Gentoo, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>getent, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>getfacl, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>getgrnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>getpwnam, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>getpwnam(), <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>GID, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Goettingen, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>government, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>GPL, <a class="indexterm" href="secure.html#id2564111">Comments Regarding Software Terms of Use</a></dt><dt>group account, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>group management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>group mapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>group membership, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>group names, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>group policies, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a></dt><dt>Group Policy, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>Group Policy editor, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>Group Policy Objects, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a></dt><dt>groupadd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>groupmem, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>groupmod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>GSS-API, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>guest account, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a>, <a class="indexterm" href="primer.html#chap01conc">Dissection and Discussion</a>, <a class="indexterm" href="primer.html#id2628227">Technical Issues</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>H</h3><dl><dt>hackers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>hardware prices, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>hardware problems, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>Heimdal, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Heimdal Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Heimdal kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>help, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>helper agent, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>hesiod, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>hierarchy of control, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>high availability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>hire, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>HKEY_CURRENT_USER, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>HKEY_LOCAL_MACHINE, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>HKEY_LOCAL_USER, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>host announcement, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a>, <a class="indexterm" href="primer.html#id2626681">Findings</a></dt><dt>hostname, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>hosts, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>HUB, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>Hybrid, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>hypothetical, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>I</h3><dl><dt>Idealx, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dd><dl><dt>smbldap-tools, <a class="indexterm" href="happy.html#sbeidealx">Install and Configure Idealx smbldap-tools Scripts</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt></dl></dd><dt>identifiers, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>identity, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>management, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt></dl></dd><dt>identity management, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Identity Management, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Identity management, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>Identity resolution, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>Identity resolver, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>IDMAP, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap backend, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>IDMAP backend, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>idmap gid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap uid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>idmap_rid, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>IMAP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>import, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>income, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>independent expert, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>inetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>inetOrgPerson, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>inheritance, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>initGrps.sh, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>initial credentials, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>inoperative, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>install, <a class="indexterm" href="upgrades.html">Updating Samba-3</a></dt><dt>installation, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>integrate, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>integrity, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>inter-domain, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>inter-operability, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>interactive help, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>interdomain trusts, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>interfaces, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>intermittent, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>internationalization, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Internet Explorer, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>Internet Information Server, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>interoperability, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>IP forwarding, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>IPC$, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>iptables, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>IRC, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>isolated, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Italian, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>J</h3><dl><dt>jobs, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>joining a domain, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt></dl></div><div class="indexdiv"><h3>K</h3><dl><dt>KDC, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dd><dl><dt>Heimdal, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>interoperability, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>libraries, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>MIT, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>unspecified fields, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>kerberos, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dd><dl><dt>server, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt></dl></dd><dt>Kerberos ticket, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>kinit, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>Kixtart, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>klist, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>krb5, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a></dt><dt>krb5.conf, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt></dl></div><div class="indexdiv"><h3>L</h3><dl><dt>LAM, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dd><dl><dt>configuration editor, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>configuration file, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>login screen, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>opening screen, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>profile, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>wizard, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt></dl></dd><dt>large domain, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>LDAP, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2573037">Preliminary Advice: Dangers Can Be Avoided</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2583767">Introduction</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>backend, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>database, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>directory, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>fail-over, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>initial configuration, <a class="indexterm" href="appendix.html#altldapcfg">Alternative LDAP Database Initialization</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>master/slave</dt><dd><dl><dt>background communication, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>preload, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>schema, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>secure, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>server, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>updates, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>ldap, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>LDAP Account Manager (see LAM)</dt><dt>LDAP backend, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>LDAP database, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>LDAP Interchange Format (see LDIF)</dt><dt>LDAP server, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>LDAP-transfer-LDIF.txt, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>ldap.conf, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>ldapadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>ldapsam, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>ldapsam backend, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>ldapsearch, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>LDIF, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2622975">Initialization of the LDAP Database</a></dt><dt>leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Lightweight Directory Access Protocol (see LDAP)</dt><dt>limit, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Linux desktop, <a class="indexterm" href="unixclients.html#id2589266">Introduction</a></dt><dt>Linux Standards Base (see LSB)</dt><dt>LMB, <a class="indexterm" href="primer.html#id2626028">Findings</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dt>LMHOSTS, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>load distribution, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>local accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Local Group Policy, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>Local Master Announcement, <a class="indexterm" href="primer.html#id2626681">Findings</a></dt><dt>Local Master Browser (see LMB)</dt><dt>localhost, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>lock directory, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>locking</dt><dd><dl><dt>Application level, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Client side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Server side, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>logging, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>login, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>loglevel, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>logon credentials, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>logon hours, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a></dt><dt>logon machines, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon path, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon process, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>logon scrip, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>logon script, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2581163">Preparation of Logon Scripts</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>logon server, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon services, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>logon time, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>logon traffic, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>logon.kix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>loopback, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>low performance, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>lower-case, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>lpadmin, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>LSB, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>M</h3><dl><dt>machine, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>machine account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>machine accounts, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>machine secret password, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a></dt><dt>MACHINE.SID, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>mailing list, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>mailing lists, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>managed, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>management, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dd><dl><dt>group, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>User, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>mandatory profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a></dt><dt>Mandrake, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>mapped drives, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>mapping, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dd><dl><dt>consistent, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt></dl></dd><dt>Mars_NWE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>master, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>material, <a class="indexterm" href="appendix.html">A Collection of Useful Tidbits</a></dt><dt>memberUID, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>memory requirements, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>merge, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>merged, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>meta-directory, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>meta-service, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Microsoft Access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft Excel, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt><dt>Microsoft ISA, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dt>Microsoft Management Console (see MMC)</dt><dt>Microsoft Office, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>Microsoft Outlook</dt><dd><dl><dt>PST files, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt></dl></dd><dt>migrate, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>migration, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2601336">Introduction</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dd><dl><dt>objectives, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd><dt>Migration speed, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mime type, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>mime types, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>missing RPC's, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>MIT, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>MIT Kerberos, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>MIT kerberos, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>MIT KRB5, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>mixed mode, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>mixed-mode, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>MMC, <a class="indexterm" href="happy.html#id2582477">Configure Delete Cached Profiles on Logout</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>mobile computing, <a class="indexterm" href="small.html#id2555545">Dissection and Discussion</a></dt><dt>mobility, <a class="indexterm" href="2000users.html#id2584139">Technical Issues</a></dt><dt>modularization, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>modules, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>MS Access</dt><dd><dl><dt>validate, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt></dl></dd><dt>MS Outlook, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>PST file, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>MS Windows Server 2003, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a></dt><dt>MS Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>MSDFS, <a class="indexterm" href="HA.html#id2620507">Distribute Network Load with MSDFS</a></dt><dt>multi-subnet, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>multi-user</dt><dd><dl><dt>access, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt><dt>data access, <a class="indexterm" href="appendix.html#ch12dblck">Shared Data Integrity</a></dt></dl></dd><dt>multiple directories, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>multiple domain controllers, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>multiple group mappings, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>mutual assistance, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>My Documents, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>My Network Places, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>mysqlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>N</h3><dl><dt>name resolution, <a class="indexterm" href="secure.html#ch4dhcpdns">Configuration of DHCP and DNS Servers</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dd><dl><dt>Defective, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>name resolve order, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>name service switch, <a class="indexterm" href="small.html#id2555812">Implementation</a> (see NSS)</dt><dt>named, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>NAT, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a></dt><dt>native, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>net</dt><dd><dl><dt>ads</dt><dd><dl><dt>info, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>join, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>status, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt></dl></dd><dt>getlocalsid, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>group, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>groupmap</dt><dd><dl><dt>add, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>list, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>modify, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt></dl></dd><dt>rpc</dt><dd><dl><dt>info, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>join, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#dcwonss">NT4/Samba Domain with Samba Domain Member Server without NSS Support</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt><dt>vampire, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a></dt></dl></dd><dt>setlocalsid, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>NetBIOS, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>name cache, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>name resolution</dt><dd><dl><dt>delays, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Node Type, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt></dl></dd><dt>netbios</dt><dd><dl><dt>machine  name, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a></dt></dl></dd><dt>netbios forwarding, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>NetBIOS name, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dd><dl><dt>aliases, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt></dl></dd><dt>netbios name, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599055">Change of hostname</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>NETLOGON, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="happy.html#id2581407">Windows Client Configuration</a></dt><dt>netlogon, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Netlogon, <a class="indexterm" href="appendix.html#domjoin">Joining a Domain: Windows 200x/XP Professional</a></dt><dt>netmask, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>Netware, <a class="indexterm" href="small.html">Small Office Networking</a></dt><dt>NetWare, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>network</dt><dd><dl><dt>administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>analyzer, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dt>bandwidth, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>broadcast, <a class="indexterm" href="primer.html#id2625592">Introduction</a></dt><dt>captures, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>collisions, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>load, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>logon scripts, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>management, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>multi-segment, <a class="indexterm" href="happy.html#id2571190">Introduction</a></dt><dt>overload, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>performance, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>routed, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>segment, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>sniffer, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>timeout, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>timeouts, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>trace, <a class="indexterm" href="primer.html#id2625652">Assignment Tasks</a></dt><dt>traffic</dt><dd><dl><dt>observation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>wide-area, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt></dl></dd><dt>Network Address Translation (see NAT)</dt><dt>network administrators, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network attached storage (see NAS)</dt><dt>network bandwidth</dt><dd><dl><dt>utilization, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>Network Default Profile, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>network hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>network hygiene, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>network Identities, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>network load factors, <a class="indexterm" href="Big500users.html#id2565398">Dissection and Discussion</a></dt><dt>Network Neighborhood, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>network segment, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>network segments, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>network share, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>networking</dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>networking hardware</dt><dd><dl><dt>defective, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>next generation, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>NextFreeUnixId, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NFS server, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>NICs, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>NIS, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>nis, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>NIS schema, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS server, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NIS+, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>nisplus, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>NLM, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>nmap, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>nmbd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>nobody, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>Novell, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a>, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>Novell SUSE SLES 9, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>NSS, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a> (see same service switch)</dt><dt>nss_ldap, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>nt acl support, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>NT4 registry, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>NTLM, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>NTLM authentication daemon, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>NTLMSSP, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>NTLMSSP_AUTH, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>ntlm_auth, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>NTP, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>NTUSER.DAT, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#id2572788">Using a Network Default User Profile</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>NULL connection, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>NULL session, <a class="indexterm" href="primer.html#id2627280">Findings and Comments</a></dt><dt>NULL-Session, <a class="indexterm" href="primer.html#id2628081">Discussion</a></dt></dl></div><div class="indexdiv"><h3>O</h3><dl><dt>objectClass, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>off-site storage, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Open Magazine, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>Open Source, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>OpenLDAP, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#id2590032">Political Issues</a>, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>openldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>OpenOffice, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>operating profiles, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>oplock break, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>oplocks, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>Oplocks</dt><dd><dl><dt>disabled, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt></dl></dd><dt>opportunistic</dt><dd><dl><dt>locking, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt></dl></dd><dt>opportunistic locking, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a>, <a class="indexterm" href="appendix.html#id2625180">Act! Database Sharing</a></dt><dt>optimized, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>organizational units, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>OS/2, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>Outlook</dt><dd><dl><dt>PST, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt></dl></dd><dt>Outlook Address Book, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>Outlook Express, <a class="indexterm" href="secure.html#id2559309">Political Issues</a>, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>over-ride, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>over-ride controls, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>over-rule, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2615027">Using MS Windows Explorer (File Manager)</a></dt><dt>overheads, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a></dt><dt>ownership, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></div><div class="indexdiv"><h3>P</h3><dl><dt>package, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt><dt>package names, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>packages, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>PADL, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a></dt><dt>PADL LDAP tools, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>PADL Software, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>paid-for support, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>PAM, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>pam_ldap, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>pam_ldap.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>pam_unix2.so, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dd><dl><dt>use_ldap, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt></dl></dd><dt>parameters, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>passdb backend, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601421">Assignment Tasks</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>passdb.tdb, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>passwd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a></dt><dt>password</dt><dd><dl><dt>backend, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>password caching, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>password change, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a></dt><dt>password length, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>payroll, <a class="indexterm" href="nw4migration.html#id2606030">Introduction</a></dt><dt>pdbedit, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>PDC, <a class="indexterm" href="Big500users.html#id2565292">Assignment Tasks</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-locgrppol">The Local Group Policy</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="ntmigration.html#id2604610">NT4 Migration Using tdbsam Backend</a>, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>PDC/BDC ratio, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>PDF, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>performance, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a>, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a>, <a class="indexterm" href="HA.html#id2618959">Introduction</a>, <a class="indexterm" href="HA.html#id2619933">Network Collisions</a></dt><dt>performance degradation, <a class="indexterm" href="kerberos.html#id2614108">Override Controls</a>, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>Perl, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>permission, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>permissions, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>excessive, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>group, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>user, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt></dl></dd><dt>Permissions, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>permits, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>permitted group, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>PHP, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>PHP4, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>pile-driver, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>ping, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>pitfalls, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>plain-text, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>Pluggable Authentication Modules (see PAM)</dt><dt>policy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>poor performance, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>POP3, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>Posix, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>POSIX, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Posix accounts, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Posix ACLs, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>PosixAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>posixAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postfix, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Postscript, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>powers, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>practices, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>precaution, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a></dt><dt>presence and leadership, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>price paid, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>primary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>principals, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>print filter, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>print queue, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>print spooler, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a></dt><dt>Print Test Page, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>printcap name, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>printer validation, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a></dt><dt>printers</dt><dd><dl><dt>Advanced, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Default Settings, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>General, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Properties, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Security, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>Sharing, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt></dl></dd><dt>printing, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dd><dl><dt>drag-and-drop, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a>, <a class="indexterm" href="happy.html#id2582657">Uploading Printer Drivers to Samba Servers</a></dt><dt>dumb, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>point-n-click, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt></dl></dd><dt>privacy, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>Privilege Attribute Certificates (see PAC)</dt><dt>privilege controls, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>privileged pipe, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>privileges, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt><dt>problem report, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>problem resolution, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>product defects, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>professional support, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>profile</dt><dd><dl><dt>default, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a></dt><dt>mandatory, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>roaming, <a class="indexterm" href="happy.html">Making Happy Users</a></dt></dl></dd><dt>profile path, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>profile share, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>profiles, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>profiles share, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>programmer, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>project, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>project maintainers, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Properties, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>proprietary, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protected, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protection, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>protocol</dt><dd><dl><dt>negotiation, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt></dl></dd><dt>protocol analysis, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>provided services, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>proxy, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>PST file, <a class="indexterm" href="happy.html#id2582162">Configuration of MS Outlook to Relocate PST File</a></dt><dt>public specifications, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>purchase support, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt></dl></div><div class="indexdiv"><h3>Q</h3><dl><dt>Qbasic, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>qualified problem, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt></dl></div><div class="indexdiv"><h3>R</h3><dl><dt>RAID, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>RAID controllers, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>Raw Print Through, <a class="indexterm" href="happy.html#id2572847">Installation of Printer Driver Auto-Download</a></dt><dt>raw printing, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4ptrcfg">Printer Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="happy.html#sbehap-ptrcfg">Printer Configuration</a></dt><dt>Rbase, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>rcldap, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>realm, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="unixclients.html#id2595406">IDMAP Storage in LDAP using Winbind</a>, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>recognize, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>record locking, <a class="indexterm" href="appendix.html#id2625032">Microsoft Access</a></dt><dt>recursively, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Red Hat, <a class="indexterm" href="simple.html#id2550946">Drafting Office</a>, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>Red Hat Fedora Linux, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Red Hat Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="simple.html#AccountingOffice">Accounting Office</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>redirected folders, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>refereed standards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>regedit, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>regedt32, <a class="indexterm" href="happy.html#id2572694">Profile Changes</a>, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dd><dl><dt>keys</dt><dd><dl><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>SECURITY, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt></dl></dd></dl></dd><dt>registry change, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Registry Editor, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>registry hacks, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>registry keys, <a class="indexterm" href="happy.html#redirfold">Configuration of Default Profile with Folder Redirection</a></dt><dt>reimburse, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>rejected, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>rejoin, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>reliability, <a class="indexterm" href="HA.html">Performance, Reliability, and Availability</a></dt><dt>remote announce, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>remote browse sync, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>remote procedure call (see RPC)</dt><dt>replicate, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>replicated, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>requesting payment, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>resilient, <a class="indexterm" href="HA.html#id2619530">Guidelines for Reliable Samba Operation</a></dt><dt>resolution, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>resolve, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="HA.html#id2619568">Bad Hostnames</a></dt><dt>response, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a></dt><dt>responsibility, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>responsible, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>restrict anonymous, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>restricted export, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>Restrictive security, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>reverse DNS, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a></dt><dt>rfc2307bis, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a></dt><dt>RID, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>risk, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>road-map, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dd><dl><dt>published, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></dd><dt>roaming profile, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>roaming profiles, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2572394">Roaming Profile Background</a></dt><dt>routed network, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a></dt><dt>router, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>routers, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>RPC, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>rpc, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>rpcclient, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>RPM, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dd><dl><dt>install, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>rpm, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>RPMs, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>rpms, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>rsync, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>rsyncd.conf, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>run-time control files, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt></dl></div><div class="indexdiv"><h3>S</h3><dl><dt>safe-guards, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SAM, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>samba, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dd><dl><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a></dt></dl></dd><dt>Samba, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Samba accounts, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>samba cluster, <a class="indexterm" href="HA.html#id2618959">Introduction</a></dt><dt>samba control script, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>Samba Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Samba Domain server, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>Samba RPM Packages, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a></dt><dt>Samba Tea, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>sambaDomainName, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>sambaGroupMapping, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaSAMAccount, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>SambaSamAccount, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>sambaSamAccount, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>SambaXP conference, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>SAN, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>SAS, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>scalability, <a class="indexterm" href="HA.html#id2618959">Introduction</a></dt><dt>scalable, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>schannel, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>schema, <a class="indexterm" href="unixclients.html#id2596001">IDMAP and NSS Using LDAP from ADS with RFC2307bis Schema Extension</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a></dt><dt>scripts, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>secondary group, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a></dt><dt>secret, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>secrets.tdb, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a></dt><dt>secure, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>secure account password, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>secure connections, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>secure networking, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>secure networking protocols, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dd><dl><dt>identifier, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>share mode, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a></dt><dt>user mode, <a class="indexterm" href="simple.html#id2553821">Dissection and Discussion</a></dt></dl></dd><dt>Security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2614736">Using the MMC Computer Management Interface</a></dt><dt>Security Account Manager (see SAM)</dt><dt>security controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security descriptors, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>security fixes, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>security updates, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SerNet, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>server</dt><dd><dl><dt>domain member, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>stand-alone, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>service, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dd><dl><dt>smb</dt><dd><dl><dt>start, <a class="indexterm" href="Big500users.html#ch5-domsvrspec">Configuration Specific to Domain Member Servers: BLDG1, BLDG2</a></dt></dl></dd></dl></dd><dt>Service Packs, <a class="indexterm" href="secure.html#ch4appscfg">Application Share Configuration</a></dt><dt>services, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt><dt>services provided, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>session setup, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>Session Setup, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></dt><dt>SessionSetUpAndX, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>set primary group script, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>setfacl, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>severely degrade, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>SFU, <a class="indexterm" href="unixclients.html#id2596287">IDMAP, Active Directory, and MS Services for UNIX 3.5</a></dt><dt>SGID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>shadow-utils, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>Share Access Controls, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>share ACLs, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>share definition, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>Share Definition</dt><dd><dl><dt>Controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a></dt></dl></dd><dt>share definition controls, <a class="indexterm" href="kerberos.html#id2613656">Share Definition Controls</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>share level access controls, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>share level ACL, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Share Permissions, <a class="indexterm" href="kerberos.html#id2613307">Share Access Controls</a></dt><dt>shared resource, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>shares, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>SID, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2594802">IDMAP_RID with Winbind</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622975">Initialization of the LDAP Database</a></dt><dt>side effects, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>Sign'n'seal, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>silent return, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a></dt><dt>simple, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>Single Sign-On (see SSO)</dt><dt>slapcat, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>slapd, <a class="indexterm" href="happy.html#id2573271">Debugging LDAP</a></dt><dt>slapd.conf, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>slave, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>slow logon, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>slow network, <a class="indexterm" href="HA.html#id2620607">Hardware Problems</a></dt><dt>slurpd, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>smart printing, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>SMB, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>SMB passwords, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>SMB/CIFS, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>smbclient, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>smbd, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#sbeug1">Location of config files</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dd><dl><dt>location of files, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt></dl></dd><dt>smbfs, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbldap-groupadd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-groupmod, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbldap-passwd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-populate, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a></dt><dt>smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a>, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>smbldap-tools updating, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>smbldap-useradd, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt><dt>smbldap-usermod, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>smbmnt, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbmount, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbpasswd, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="happy.html#id2576854">LDAP Initialization and Creation of User and Group Accounts</a>, <a class="indexterm" href="happy.html#sbehap-bldg1">Samba-3 BDC Configuration</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html">Updating Samba-3</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="DomApps.html">Integrating Additional Services</a></dt><dt>smbumnt, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>smbumount, <a class="indexterm" href="HA.html#id2619057">Dissection and Discussion</a></dt><dt>SMTP, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a></dt><dt>snap-shot, <a class="indexterm" href="ntmigration.html#id2601476">Dissection and Discussion</a></dt><dt>socket address, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>socket options, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>software, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>solve, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>source code, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>SPNEGO, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>SQL, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>Squid, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617976">Squid Configuration</a></dt><dt>squid, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>Squid proxy, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>SRVTOOLS.EXE, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="happy.html#id2580918">Configuring Profile Directories</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>SSL, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>stand-alone server, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>starting CUPS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting dhcpd, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dt>starting samba, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a>, <a class="indexterm" href="Big500users.html#ch5-procstart">Process Startup Configuration</a></dt><dd><dl><dt>nmbd, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>smbd, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>winbindd, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt></dl></dd><dt>startingCUPS, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a></dt><dt>startup script, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>sticky bit, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt><dt>storage capacity, <a class="indexterm" href="secure.html#id2559155">Hardware Requirements</a></dt><dt>strategic, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a></dt><dt>strategy, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>straw-man, <a class="indexterm" href="kerberos.html">Active Directory, Kerberos, and Security</a></dt><dt>strict sync, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>stripped, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a></dt><dt>strong cryptography, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>subscription, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>SUID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a>, <a class="indexterm" href="appendix.html#ch12-SUIDSGID">Effect of Setting File and Directory SUID/SGID Permissions Explained</a></dt><dt>Sun ONE Identity Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>super daemon, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>support, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a>, <a class="indexterm" href="ch14.html">Samba Support</a></dt><dt>survey, <a class="indexterm" href="unixclients.html">Adding Domain Member Servers and Clients</a></dt><dt>SUSE, <a class="indexterm" href="nw4migration.html">Migrating NetWare Server to Samba-3</a></dt><dt>SUSE Enterprise Linux Server, <a class="indexterm" href="simple.html#id2551655">Charity Administration Office</a>, <a class="indexterm" href="secure.html#ch4bsc">Basic System Configuration</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a></dt><dt>SUSE Linux, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2573956">Samba Server Implementation</a>, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2616520">Implementation</a>, <a class="indexterm" href="DomApps.html#ch10-one">Removal of Pre-Existing Conflicting RPMs</a></dt><dt>SWAT, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>sync always, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>synchronization, <a class="indexterm" href="DomApps.html#id2616769">Kerberos Configuration</a>, <a class="indexterm" href="HA.html#id2620457">For Scalability, Use SAN-Based Storage on Samba Servers</a></dt><dt>synchronize, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>synchronized, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>syslog, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>system level logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>system security, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>T</h3><dl><dt>tattooing, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>TCP/IP, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>tdbdump, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>tdbsam, <a class="indexterm" href="secure.html#id2558882">Technical Issues</a>, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="happy.html#id2571288">Assignment Tasks</a>, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="upgrades.html#id2600580">Updating from Samba Versions between 3.0.6 and 3.0.10</a>, <a class="indexterm" href="ntmigration.html#id2601662">Technical Issues</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>testparm, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="happy.html#sbehap-massive">Samba-3 PDC Configuration</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="HA.html#id2620033">Samba Configuration</a></dt><dt>ticket, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>time server, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>Tivoli Directory Server, <a class="indexterm" href="happy.html#id2571425">Dissection and Discussion</a></dt><dt>TLS, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>token, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a></dt><dt>tool, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>TOSHARG2, <a class="indexterm" href="simple.html#id2551974">Implementation</a></dt><dt>track record, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>traffic collisions, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>transaction processing, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>transactional, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>transfer, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>translate, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>traverse, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>tree, <a class="indexterm" href="nw4migration.html#id2606260">Dissection and Discussion</a></dt><dt>Tree Connect, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></dt><dt>trust account, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a></dt><dt>trusted computing, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Trusted Domains, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>trusted domains, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>trusted third-party, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>trusting, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>turn-around time, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt></dl></div><div class="indexdiv"><h3>U</h3><dl><dt>UDP</dt><dd><dl><dt>broadcast, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt></dl></dd><dt>UID, <a class="indexterm" href="simple.html#id2551779">Dissection and Discussion</a>, <a class="indexterm" href="happy.html#id2571048">Regarding LDAP Directories and Windows Computer Accounts</a>, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a>, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>un-join, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>unauthorized activities, <a class="indexterm" href="kerberos.html#id2612961">Kerberos Exposed</a></dt><dt>UNC name, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>unencrypted, <a class="indexterm" href="appendix.html#id2623561">The LDAP Account Manager</a></dt><dt>Unicast, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a></dt><dt>unicode, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>Universal Naming Convention (see UNC name)</dt><dt>UNIX, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>groups, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a></dt></dl></dd><dt>UNIX accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>UNIX/Linux server, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unix2dos, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt><dt>unknown, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>unsupported software, <a class="indexterm" href="ch14.html#id2621247">Commercial Support</a></dt><dt>update, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a></dt><dt>updates, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>updating smbldap-tools, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>upgrade, <a class="indexterm" href="upgrades.html#id2598126">Introduction</a>, <a class="indexterm" href="upgrades.html#id2598223">Cautions and Notes</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>uppercase, <a class="indexterm" href="ntmigration.html#id2602011">Implementation</a></dt><dt>user</dt><dd><dl><dt>management, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a></dt></dl></dd><dt>user account, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="happy.html#ldapsetup">OpenLDAP Server Configuration</a></dt><dt>User and Group Controls, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>user credentials, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#id2596338">UNIX/Linux Client Domain Member</a></dt><dt>user errors, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user groups, <a class="indexterm" href="ch14.html#id2621028">Free Support</a></dt><dt>user identities, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>user logins, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>user management, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>User Manager, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>User Mode, <a class="indexterm" href="secure.html#id2559348">Implementation</a>, <a class="indexterm" href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a>, <a class="indexterm" href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></dt><dt>useradd, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="simple.html#AcctgNet">Implementation</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566965">Configuration for Server: MASSIVE</a>, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>userdel, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a></dt><dt>usermod, <a class="indexterm" href="upgrades.html#id2599920">Applicable to All Samba 2.x to Samba-3 Upgrades</a>, <a class="indexterm" href="ntmigration.html#id2602152">NT4 Migration Using LDAP Backend</a></dt><dt>username, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>username map, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#id2560202">Samba Configuration</a>, <a class="indexterm" href="Big500users.html#id2566387">Server Preparation: All Servers</a></dt><dt>UTF-8, <a class="indexterm" href="upgrades.html#id2599386">International Language Support</a></dt><dt>utilities, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt></dl></div><div class="indexdiv"><h3>V</h3><dl><dt>valid users, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a>, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>validate, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>validated, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>validation, <a class="indexterm" href="simple.html#validate1">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>vampire, <a class="indexterm" href="ntmigration.html#id2605055">Questions and Answers</a></dt><dt>vendor, <a class="indexterm" href="kerberos.html#id2611280">Dissection and Discussion</a></dt><dt>vendors, <a class="indexterm" href="upgrades.html#id2600436">Updating a Samba-3 Installation</a></dt><dt>VFS modules, <a class="indexterm" href="appendix.html#id2621955">Samba System File Location</a></dt><dt>virus, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>VPN, <a class="indexterm" href="2000users.html#id2583797">Assignment Tasks</a></dt><dt>vulnerabilities, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt></dl></div><div class="indexdiv"><h3>W</h3><dl><dt>wbinfo, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#adssdm">Active Directory Domain with Samba Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a></dt><dt>weakness, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a></dt><dt>web</dt><dd><dl><dt>caching, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt><dt>proxying, <a class="indexterm" href="DomApps.html#id2616202">Assignment Tasks</a></dt></dl></dd><dt>Web</dt><dd><dl><dt>proxy, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dd><dl><dt>access, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt></dl></dd></dl></dd><dt>Web browsers, <a class="indexterm" href="DomApps.html#id2618372">Key Points Learned</a></dt><dt>WebClient, <a class="indexterm" href="happy.html">Making Happy Users</a></dt><dt>WHATSNEW.txt, <a class="indexterm" href="upgrades.html#id2600254">Samba-2.x with LDAP Support</a></dt><dt>white-pages, <a class="indexterm" href="nw4migration.html#id2606337">Technical Issues</a>, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>wide-area, <a class="indexterm" href="2000users.html#id2584178">User Needs</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588260">Key Points Learned</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>wide-area network, <a class="indexterm" href="HA.html#id2620360">Use and Location of BDCs</a>, <a class="indexterm" href="HA.html#id2620562">Replicate Data to Conserve Peak-Demand Wide-Area Bandwidth</a></dt><dt>winbind, <a class="indexterm" href="2000users.html#id2585101">Implementation</a>, <a class="indexterm" href="unixclients.html#id2589354">Dissection and Discussion</a>, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2616346">Technical Issues</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2617710">NSS Configuration</a></dt><dt>Winbind, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="kerberos.html#id2611677">Technical Issues</a>, <a class="indexterm" href="kerberos.html#id2615408">Key Points Learned</a></dt><dt>winbind trusted domains only, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>winbind use default domain, <a class="indexterm" href="kerberos.html#id2613795">Checkpoint Controls</a></dt><dt>winbindd, <a class="indexterm" href="small.html#id2557356">Validation</a>, <a class="indexterm" href="secure.html#ch4valid">Validation</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a>, <a class="indexterm" href="unixclients.html#sdcsdmldap">Samba Domain with Samba Domain Member Server  Using NSS LDAP</a>, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a>, <a class="indexterm" href="upgrades.html#sbeug2">Samba 1.9.x and 2.x Versions Without LDAP</a>, <a class="indexterm" href="upgrades.html#id2600658">Updating from Samba Versions after 3.0.6 to a Current Release</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a>, <a class="indexterm" href="DomApps.html#id2617158">Samba Configuration</a>, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a>, <a class="indexterm" href="appendix.html#id2622376">Starting Samba</a></dt><dt>winbindd_cache.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>winbindd_idmap.tdb, <a class="indexterm" href="unixclients.html#id2589383">Technical Issues</a></dt><dt>Windows, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dd><dl><dt>client, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt><dt>NT, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a></dt></dl></dd><dt>Windows 2000 ACLs, <a class="indexterm" href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></dt><dt>Windows 2003 Serve, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows 200x ACLs, <a class="indexterm" href="kerberos.html#id2615543">Questions and Answers</a></dt><dt>Windows accounts, <a class="indexterm" href="happy.html#id2571882">Technical Issues</a></dt><dt>Windows ACLs, <a class="indexterm" href="kerberos.html#id2615198">Setting Posix ACLs in UNIX/Linux</a></dt><dt>Windows Address Book, <a class="indexterm" href="nw4migration.html#id2606611">LDAP Server Configuration</a></dt><dt>Windows ADS Domain, <a class="indexterm" href="unixclients.html#wdcsdm">NT4/Samba Domain with Samba Domain Member Server: Using NSS and Winbind</a></dt><dt>Windows clients, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>Windows Explorer, <a class="indexterm" href="simple.html#validate1">Validation</a></dt><dt>Windows explorer, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>Windows security identifier (see SID)</dt><dt>Windows Servers, <a class="indexterm" href="kerberos.html#id2610613">Introduction</a></dt><dt>Windows Services for UNIX (see SUS)</dt><dt>Windows XP, <a class="indexterm" href="small.html#id2555484">Assignment Tasks</a></dt><dt>WINS, <a class="indexterm" href="simple.html#id2551974">Implementation</a>, <a class="indexterm" href="small.html#id2555593">Technical Issues</a>, <a class="indexterm" href="small.html#id2555812">Implementation</a>, <a class="indexterm" href="secure.html#ch4wincfg">Windows Client Configuration</a>, <a class="indexterm" href="Big500users.html#id2565433">Technical Issues</a>, <a class="indexterm" href="Big500users.html#ch5wincfg">Windows Client Configuration</a>, <a class="indexterm" href="2000users.html#id2584272">The Nature of Windows Networking Protocols</a>, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a>, <a class="indexterm" href="primer.html#chap01qa">Questions and Answers</a></dt><dd><dl><dt>lookup, <a class="indexterm" href="unixclients.html#id2596967">Questions and Answers</a></dt><dt>name resolution, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt><dt>server, <a class="indexterm" href="happy.html">Making Happy Users</a>, <a class="indexterm" href="HA.html#id2619760">Routed Networks</a></dt></dl></dd><dt>WINS server, <a class="indexterm" href="Big500users.html">The 500-User Office</a>, <a class="indexterm" href="2000users.html#id2588407">Questions and Answers</a></dt><dt>WINS serving, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins support, <a class="indexterm" href="secure.html#id2559348">Implementation</a></dt><dt>wins.dat, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a>, <a class="indexterm" href="upgrades.html#id2600761">Replacing a Domain Member Server</a></dt><dt>Wireshark, <a class="indexterm" href="primer.html#id2625430">Requirements and Notes</a></dt><dt>wireshark, <a class="indexterm" href="primer.html#id2625769">Exercises</a></dt><dt>Word, <a class="indexterm" href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></dt><dt>workgroup, <a class="indexterm" href="simple.html#id2551082">Implementation</a>, <a class="indexterm" href="upgrades.html#id2598326">Security Identifiers (SIDs)</a>, <a class="indexterm" href="upgrades.html#id2599120">Change of Workgroup (Domain) Name</a></dt><dt>Workgroup Announcement, <a class="indexterm" href="primer.html#id2626681">Findings</a></dt><dt>workstation, <a class="indexterm" href="unixclients.html#id2590132">Implementation</a></dt><dt>wrapper, <a class="indexterm" href="DomApps.html#id2618432">Questions and Answers</a></dt><dt>write lock, <a class="indexterm" href="appendix.html#id2625264">Opportunistic Locking Controls</a></dt></dl></div><div class="indexdiv"><h3>X</h3><dl><dt>xinetd, <a class="indexterm" href="secure.html#procstart">Process Startup Configuration</a></dt><dt>XML, <a class="indexterm" href="2000users.html#id2583865">Dissection and Discussion</a></dt><dt>xmlsam, <a class="indexterm" href="2000users.html#id2585101">Implementation</a></dt></dl></div><div class="indexdiv"><h3>Y</h3><dl><dt>YaST, <a class="indexterm" href="happy.html#sbehap-PAM-NSS">PAM and NSS Client Configuration</a></dt><dt>Yellow Pages, <a class="indexterm" href="2000users.html#id2584619">Identity Management Needs</a></dt><dt>yellow pages (see NIS)</dt></dl></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="go01.html">Prev</a> </td><td width="20%" align="center"> </td><td width="40%" align="right"> </td></tr><tr><td width="40%" align="left" valign="top">Glossary </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> </td></tr></table></div></body></html>
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/kerberos.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 11. Active Directory, Kerberos, and Security</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="RefSection.html" title="Part III. Reference Section"><link rel="next" href="DomApps.html" title="Chapter 12. Integrating Additional Services"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 11. Active Directory, Kerberos, and Security</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="RefSection.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="DomApps.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="kerberos"></a>Chapter 11. Active Directory, Kerberos, and Security</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614672">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615399">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615533">Questions and Answers</a></span></dt></dl></div><p><a class="indexterm" name="id2610549"></a>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 11. Active Directory, Kerberos, and Security</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="RefSection.html" title="Part III. Reference Section"><link rel="next" href="DomApps.html" title="Chapter 12. Integrating Additional Services"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 11. Active Directory, Kerberos, and Security</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="RefSection.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="DomApps.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="kerberos"></a>Chapter 11. Active Directory, Kerberos, and Security</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="kerberos.html#id2610613">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611264">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2611280">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2611677">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#ch10expl">Implementation</a></span></dt><dd><dl><dt><span class="sect2"><a href="kerberos.html#id2613307">Share Access Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2613656">Share Definition Controls</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614269">Share Point Directory and File Permissions</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2614682">Managing Windows 200x ACLs</a></span></dt><dt><span class="sect2"><a href="kerberos.html#id2615408">Key Points Learned</a></span></dt></dl></dd><dt><span class="sect1"><a href="kerberos.html#id2615543">Questions and Answers</a></span></dt></dl></div><p><a class="indexterm" name="id2610549"></a>
    22        By this point in the book, you have been exposed to many Samba-3 features and capabilities.
    33        More importantly, if you have implemented the examples given, you are well on your way to becoming
     
    527527        Microsoft Office files (Word and Excel) to a network drive. Here is the typical sequence:
    528528        </p><div class="orderedlist"><ol type="1"><li><p>
    529                 A user opens a Work document from a network drive. The file was owned by user <code class="constant">janetp</code>
     529                A user opens a Word document from a network drive. The file was owned by user <code class="constant">janetp</code>
    530530                and  [users], and was set read/write-enabled for everyone.
     531                A user opens a Word document from a network drive. The file was owned by user <code class="constant">janetp</code>
     532                and <code class="constant">users</code>, and was set read/write-enabled for everyone.
    531533                </p></li><li><p>
    532534                File changes and edits are made.
     
    543545        want to know when this &#8220;<span class="quote">bug</span>&#8221; will be fixed. The fact is, this is not a bug in Samba at all.
    544546        Here is the real sequence of what happens in this case.
    545         </p><p><a class="indexterm" name="id2614430"></a><a class="indexterm" name="id2614438"></a><a class="indexterm" name="id2614446"></a>
     547        </p><p><a class="indexterm" name="id2614440"></a><a class="indexterm" name="id2614448"></a><a class="indexterm" name="id2614456"></a>
    546548        When the user saves a file, MS Word creates a new (temporary) file. This file is naturally owned
    547549        by the user who creates the file (<code class="constant">billc</code>) and has the permissions that follow
     
    561563        simple steps to create a share in which all files will consistently be owned by the same user and the
    562564        same group:
    563         </p><div class="procedure"><a name="id2614493"></a><p class="title"><b>Procedure 11.2. Using Directory Permissions to Force File User and Group Ownership</b></p><ol type="1"><li><p>
     565        </p><div class="procedure"><a name="id2614502"></a><p class="title"><b>Procedure 11.2. Using Directory Permissions to Force File User and Group Ownership</b></p><ol type="1"><li><p>
    564566                Change your share definition so that it matches this pattern:
    565567</p><pre class="screen">
     
    569571        read only = No
    570572</pre><p>
    571                 </p></li><li><p><a class="indexterm" name="id2614519"></a><a class="indexterm" name="id2614530"></a>
     573                </p></li><li><p><a class="indexterm" name="id2614528"></a><a class="indexterm" name="id2614539"></a>
    572574                Set consistent user and group permissions recursively down the directory tree as shown here:
    573575</p><pre class="screen">
    574576<code class="prompt">root# </code> chown -R janetp.users /usr/data/finance
    575577</pre><p>
    576                 </p></li><li><p><a class="indexterm" name="id2614562"></a>
     578                </p></li><li><p><a class="indexterm" name="id2614571"></a>
    577579                Set the files and directory permissions to be read/write for owner and group, and not accessible
    578580                to others (everyone), using the following command:
     
    580582<code class="prompt">root# </code> chmod ug+rwx,o-rwx /usr/data/finance
    581583</pre><p>
    582                 </p></li><li><p><a class="indexterm" name="id2614591"></a>
     584                </p></li><li><p><a class="indexterm" name="id2614600"></a>
    583585                Set the SGID (supergroup) bit on all directories from the top down. This means all files
    584586                can be created with the permissions of the group set on the directory. It means all users
     
    590592</pre><p>
    591593
    592                 </p></li><li><p><a class="indexterm" name="id2614631"></a><a class="indexterm" name="id2614639"></a><a class="indexterm" name="id2614647"></a>
     594                </p></li><li><p><a class="indexterm" name="id2614641"></a><a class="indexterm" name="id2614649"></a><a class="indexterm" name="id2614657"></a>
    593595                Make sure all users that must have read/write access to the directory have
    594596                <code class="constant">finance</code> group membership as their primary group,
    595597                for example, the group they belong to in <code class="filename">/etc/passwd</code>.
    596                 </p></li></ol></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2614672"></a>Managing Windows 200x ACLs</h3></div></div></div><p><a class="indexterm" name="id2614679"></a><a class="indexterm" name="id2614687"></a><a class="indexterm" name="id2614695"></a><a class="indexterm" name="id2614703"></a>
     598                </p></li></ol></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2614682"></a>Managing Windows 200x ACLs</h3></div></div></div><p><a class="indexterm" name="id2614688"></a><a class="indexterm" name="id2614696"></a><a class="indexterm" name="id2614704"></a><a class="indexterm" name="id2614712"></a>
    597599        Samba must translate Windows 2000 ACLs to UNIX POSIX ACLs. This has some interesting side effects because
    598600        there is not a one-to-one equivalence between them. The as-close-as-possible ACLs match means
     
    602604        There are two possible ways to set ACLs on UNIX/Linux file systems from a Windows network workstation,
    603605        either via File Manager or via the Microsoft Management Console (MMC) Computer Management interface.
    604         </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2614727"></a>Using the MMC Computer Management Interface</h4></div></div></div><div class="procedure"><ol type="1"><li><p>
     606        </p><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2614736"></a>Using the MMC Computer Management Interface</h4></div></div></div><div class="procedure"><ol type="1"><li><p>
    605607                From a Windows 200x/XP Professional workstation, log on to the domain using the Domain Administrator
    606608                account (on Samba domains, this is usually the account called <code class="constant">root</code>).
     
    617619                </p></li><li><p>
    618620                In the left panel, click <span class="guimenu">Computer Management (FRODO)</span> &#8594; <span class="guimenuitem">[+] Shared Folders</span> &#8594; <span class="guimenuitem">Shares</span>.
    619                 </p></li><li><p><a class="indexterm" name="id2614910"></a><a class="indexterm" name="id2614918"></a><a class="indexterm" name="id2614925"></a><a class="indexterm" name="id2614933"></a>
     621                </p></li><li><p><a class="indexterm" name="id2614919"></a><a class="indexterm" name="id2614927"></a><a class="indexterm" name="id2614935"></a><a class="indexterm" name="id2614943"></a>
    620622                In the right panel, double-click on the share on which you wish to set/edit ACLs. This
    621623                brings up the Properties panel. Click the <span class="guimenu">Security</span> tab. It is best
     
    624626                functionality under the <code class="constant">Permissions</code> tab can be utilized with respect
    625627                to a Samba domain server.
    626                 </p></li><li><p><a class="indexterm" name="id2614973"></a><a class="indexterm" name="id2614981"></a>
     628                </p></li><li><p><a class="indexterm" name="id2614982"></a><a class="indexterm" name="id2614990"></a>
    627629                You may now edit/add/remove access control settings. Be very careful. Many problems have been
    628630                created by people who decided that everyone should be rejected but one particular group should
     
    633635                When you are done with editing, close all panels by clicking through the <span class="guimenu">OK</span>
    634636                buttons until the last panel closes.
    635                 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2615018"></a>Using MS Windows Explorer (File Manager)</h4></div></div></div><p>
     637                </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2615027"></a>Using MS Windows Explorer (File Manager)</h4></div></div></div><p>
    636638        The following alternative method may be used from a Windows workstation. In this example we work
    637639        with a domain called <code class="constant">MEGANET</code>, a server called <code class="constant">MASSIVE</code>, and a
     
    641643                Click <span class="guimenu">Start</span> &#8594; <span class="guimenuitem">[right-click] My Computer</span> &#8594; <span class="guimenuitem">Explore</span> &#8594; <span class="guimenuitem">[left panel] [+] My Network Places</span> &#8594; <span class="guimenuitem">[+] Entire Network</span> &#8594; <span class="guimenuitem">[+] Microsoft Windows Network</span> &#8594; <span class="guimenuitem">[+] Meganet</span> &#8594; <span class="guimenuitem">[+] Massive</span> &#8594; <span class="guimenuitem">[right-click] Apps</span> &#8594; <span class="guimenuitem">Properties</span> &#8594; <span class="guimenuitem">Security</span> &#8594; <span class="guimenuitem">Advanced</span>. This opens a panel that has four tabs. Only the functionality under the
    642644                <code class="constant">Permissions</code> tab can be utilized for a Samba domain server.
    643                 </p></li><li><p><a class="indexterm" name="id2615142"></a><a class="indexterm" name="id2615150"></a>
     645                </p></li><li><p><a class="indexterm" name="id2615152"></a><a class="indexterm" name="id2615160"></a>
    644646                You may now edit/add/remove access control settings. Be very careful. Many problems have been
    645647                created by people who decided that everyone should be rejected but one particular group should
     
    650652                When you are done with editing, close all panels by clicking through the <span class="guimenu">OK</span>
    651653                buttons until the last panel closes.
    652                 </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2615189"></a>Setting Posix ACLs in UNIX/Linux</h4></div></div></div><p><a class="indexterm" name="id2615196"></a><a class="indexterm" name="id2615204"></a>
     654                </p></li></ol></div></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2615198"></a>Setting Posix ACLs in UNIX/Linux</h4></div></div></div><p><a class="indexterm" name="id2615205"></a><a class="indexterm" name="id2615213"></a>
    653655        Yet another alternative method for setting desired security settings on the shared resource files and
    654656        directories can be achieved by logging into UNIX/Linux and setting POSIX ACLs directly using command-line
     
    673675other::r-x
    674676</pre><p>
    675                 </p></li><li><p><a class="indexterm" name="id2615278"></a>
     677                </p></li><li><p><a class="indexterm" name="id2615287"></a>
    676678                You want to add permission for <code class="constant">AppsMgrs</code> to enable them to
    677679                manage the applications (apps) share. It is important to set the ACL recursively
     
    696698</pre><p>
    697699                This confirms that the change of POSIX ACL permissions has been effective.
    698                 </p></li><li><p><a class="indexterm" name="id2615334"></a><a class="indexterm" name="id2615341"></a><a class="indexterm" name="id2615349"></a><a class="indexterm" name="id2615357"></a><a class="indexterm" name="id2615365"></a>
     700                </p></li><li><p><a class="indexterm" name="id2615343"></a><a class="indexterm" name="id2615351"></a><a class="indexterm" name="id2615359"></a><a class="indexterm" name="id2615367"></a><a class="indexterm" name="id2615375"></a>
    699701                It is highly recommended that you read the online manual page for the <code class="literal">setfacl</code>
    700702                and <code class="literal">getfacl</code> commands. This provides information regarding how to set/read the default
    701703                ACLs and how that may be propagated through the directory tree. In Windows ACLs terms, this is the equivalent
    702704                of setting <code class="constant">inheritance</code> properties.
    703                 </p></li></ol></div></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2615399"></a>Key Points Learned</h3></div></div></div><p>
     705                </p></li></ol></div></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2615408"></a>Key Points Learned</h3></div></div></div><p>
    704706                The mish-mash of issues were thrown together into one chapter because it seemed like a good idea.
    705707                Looking back, this chapter could be broken into two, but it's too late now. It has been done.
    706708                The highlights covered are as follows:
    707                 </p><div class="itemizedlist"><ul type="disc"><li><p><a class="indexterm" name="id2615416"></a><a class="indexterm" name="id2615424"></a><a class="indexterm" name="id2615432"></a><a class="indexterm" name="id2615440"></a>
     709                </p><div class="itemizedlist"><ul type="disc"><li><p><a class="indexterm" name="id2615426"></a><a class="indexterm" name="id2615434"></a><a class="indexterm" name="id2615442"></a><a class="indexterm" name="id2615450"></a>
    708710                        Winbind honors and does not override account controls set in Active Directory.
    709711                        This means that password change, logon hours, and so on, are (or soon will be) enforced
     
    711713                        change is enforced. At this time, if logon hours expire, the user is not forcibly
    712714                        logged off. That may be implemented at some later date.
    713                         </p></li><li><p><a class="indexterm" name="id2615459"></a><a class="indexterm" name="id2615467"></a>
     715                        </p></li><li><p><a class="indexterm" name="id2615468"></a><a class="indexterm" name="id2615476"></a>
    714716                        Sign'n'seal (plus schannel support) has been implemented in Samba-3. Beware of potential
    715717                        problems acknowledged by Microsoft as having been fixed but reported by some as still
    716718                        possibly an open issue.
    717                         </p></li><li><p><a class="indexterm" name="id2615483"></a><a class="indexterm" name="id2615491"></a><a class="indexterm" name="id2615498"></a><a class="indexterm" name="id2615506"></a>
     719                        </p></li><li><p><a class="indexterm" name="id2615492"></a><a class="indexterm" name="id2615500"></a><a class="indexterm" name="id2615508"></a><a class="indexterm" name="id2615516"></a>
    718720                        The combination of Kerberos 5, plus OpenLDAP, plus Samba, cannot replace Microsoft
    719721                        Active Directory. The possibility to do this is not planned in the current Samba-3
     
    724726                        the four key methodologies was reviewed with specific reference to example deployment
    725727                        techniques.
    726                         </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2615533"></a>Questions and Answers</h2></div></div></div><p>
    727         </p><div class="qandaset"><dl><dt> <a href="kerberos.html#id2615549">
     728                        </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2615543"></a>Questions and Answers</h2></div></div></div><p>
     729        </p><div class="qandaset"><dl><dt> <a href="kerberos.html#id2615558">
    728730                Does Samba-3 require the Sign'n'seal registry hacks needed by Samba-2?
    729                 </a></dt><dt> <a href="kerberos.html#id2615619">
     731                </a></dt><dt> <a href="kerberos.html#id2615629">
    730732                Does Samba-3 support Active Directory?
    731                 </a></dt><dt> <a href="kerberos.html#id2615650">
     733                </a></dt><dt> <a href="kerberos.html#id2615660">
    732734                When Samba-3 is used with Active Directory, is it necessary to run mixed-mode operation, as was
    733735                necessary with Samba-2?
    734                 </a></dt><dt> <a href="kerberos.html#id2615689">
     736                </a></dt><dt> <a href="kerberos.html#id2615698">
    735737                Is it safe to set share-level access controls in Samba?
    736                 </a></dt><dt> <a href="kerberos.html#id2615718">
     738                </a></dt><dt> <a href="kerberos.html#id2615728">
    737739                Is it mandatory to set share ACLs to get a secure Samba-3 server?
    738                 </a></dt><dt> <a href="kerberos.html#id2615795">
     740                </a></dt><dt> <a href="kerberos.html#id2615804">
    739741                The valid users did not work on the [homes].
    740742                Has this functionality been restored yet?
    741                 </a></dt><dt> <a href="kerberos.html#id2615861">
     743                </a></dt><dt> <a href="kerberos.html#id2615870">
    742744                Is the bias against use of the force user and force group
    743745                really warranted?
    744                 </a></dt><dt> <a href="kerberos.html#id2615924">
     746                </a></dt><dt> <a href="kerberos.html#id2615934">
    745747                The example given for file and directory access control forces all files to be owned by one
    746748                particular user. I do not like that. Is there any way I can see who created the file?
    747                 </a></dt><dt> <a href="kerberos.html#id2615972">
     749                </a></dt><dt> <a href="kerberos.html#id2615982">
    748750                In the book, &#8220;The Official Samba-3 HOWTO and Reference Guide&#8221;, you recommended use
    749751                of the Windows NT4 Server Manager (part of the SRVTOOLS.EXE) utility. Why
    750752                have you mentioned only the use of the Windows 200x/XP MMC Computer Management utility?
    751                 </a></dt><dt> <a href="kerberos.html#id2616039">
     753                </a></dt><dt> <a href="kerberos.html#id2616048">
    752754                I tried to set valid users = @Engineers, but it does not work. My Samba
    753755                server is an Active Directory domain member server. Has this been fixed now?
    754                 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2615549"></a><a name="id2615551"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615554"></a><a class="indexterm" name="id2615562"></a>
     756                </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2615558"></a><a name="id2615561"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615564"></a><a class="indexterm" name="id2615572"></a>
    755757                Does Samba-3 require the <code class="constant">Sign'n'seal</code> registry hacks needed by Samba-2?
    756                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615582"></a><a class="indexterm" name="id2615589"></a><a class="indexterm" name="id2615597"></a>
     758                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615591"></a><a class="indexterm" name="id2615599"></a><a class="indexterm" name="id2615607"></a>
    757759                No. Samba-3 fully supports <code class="constant">Sign'n'seal</code> as well as <code class="constant">schannel</code>
    758760                operation. The registry change should not be applied when Samba-3 is used as a domain controller.
    759                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615619"></a><a name="id2615622"></a></td><td align="left" valign="top"><p>
     761                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615629"></a><a name="id2615631"></a></td><td align="left" valign="top"><p>
    760762                Does Samba-3 support Active Directory?
    761                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615632"></a>
     763                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615642"></a>
    762764                Yes. Samba-3 can be a fully participating native mode Active Directory client. Samba-3 does not
    763765                provide Active Directory services. It cannot be used to replace a Microsoft Active Directory
    764766                server implementation. Samba-3 can function as an Active Directory client (workstation) toolkit,
    765767                and it can function as an Active Directory domain member server.
    766                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615650"></a><a name="id2615653"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615656"></a>
     768                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615660"></a><a name="id2615662"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615665"></a>
    767769                When Samba-3 is used with Active Directory, is it necessary to run mixed-mode operation, as was
    768770                necessary with Samba-2?
    769                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615672"></a>
     771                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615682"></a>
    770772                No. Samba-3 can be used with NetBIOS over TCP/IP disabled, just as can be done with Windows 200x
    771773                Server and 200x/XPPro client products. It is no longer necessary to run mixed-mode operation,
    772774                because Samba-3 can join a native Windows 2003 Server ADS domain.
    773                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615689"></a><a name="id2615691"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615694"></a>
     775                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615698"></a><a name="id2615701"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615704"></a>
    774776                Is it safe to set share-level access controls in Samba?
    775777                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
     
    777779                very mature technology. Not enough sites make use of this powerful capability, neither on
    778780                Windows server or with Samba servers.
    779                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615718"></a><a name="id2615720"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615724"></a>
     781                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615728"></a><a name="id2615730"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615733"></a>
    780782                Is it mandatory to set share ACLs to get a secure Samba-3 server?
    781                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615739"></a><a class="indexterm" name="id2615747"></a><a class="indexterm" name="id2615755"></a><a class="indexterm" name="id2615764"></a><a class="indexterm" name="id2615772"></a>
     783                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615749"></a><a class="indexterm" name="id2615757"></a><a class="indexterm" name="id2615765"></a><a class="indexterm" name="id2615773"></a><a class="indexterm" name="id2615781"></a>
    782784                No. Samba-3 honors UNIX/Linux file system security, supports Windows 200x ACLs, and provides
    783785                means of securing shares through share definition controls in the <code class="filename">smb.conf</code> file. The additional
    784786                support for share-level ACLs is like frosting on the cake. It adds to security but is not essential
    785787                to it.
    786                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615795"></a><a name="id2615797"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615800"></a>
     788                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615804"></a><a name="id2615806"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615810"></a>
    787789                The <em class="parameter"><code>valid users</code></em> did not work on the <em class="parameter"><code>[homes]</code></em>.
    788790                Has this functionality been restored yet?
    789                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615828"></a>
     791                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615837"></a>
    790792                Yes. This was fixed in Samba-3.0.2. The use of this parameter is strongly recommended as a safeguard
    791793                on the <em class="parameter"><code>[homes]</code></em> meta-service. The correct way to specify this is:
    792794                <a class="link" href="smb.conf.5.html#VALIDUSERS" target="_top">valid users = %S</a>.
    793                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615861"></a><a name="id2615863"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615866"></a><a class="indexterm" name="id2615874"></a><a class="indexterm" name="id2615882"></a>
     795                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615870"></a><a name="id2615872"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615876"></a><a class="indexterm" name="id2615883"></a><a class="indexterm" name="id2615891"></a>
    794796                Is the bias against use of the <em class="parameter"><code>force user</code></em> and <em class="parameter"><code>force group</code></em>
    795797                really warranted?
    796                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615909"></a>
     798                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615918"></a>
    797799                There is no bias. There is a determination to recommend the right tool for the task at hand.
    798800                After all, it is better than putting users through performance problems, isn't it?
    799                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615924"></a><a name="id2615926"></a></td><td align="left" valign="top"><p>
     801                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615934"></a><a name="id2615936"></a></td><td align="left" valign="top"><p>
    800802                The example given for file and directory access control forces all files to be owned by one
    801803                particular user. I do not like that. Is there any way I can see who created the file?
    802                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615939"></a>
     804                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2615948"></a>
    803805                Sure. You do not have to set the SUID bit on the directory. Simply execute the following command
    804806                to permit file ownership to be retained by the user who created it:
     
    808810                Note that this required no more than removing the <code class="constant">u</code> argument so that the
    809811                SUID bit is not set for the owner.
    810                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615972"></a><a name="id2615974"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615978"></a>
     812                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2615982"></a><a name="id2615984"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2615987"></a>
    811813                In the book, &#8220;<span class="quote">The Official Samba-3 HOWTO and Reference Guide</span>&#8221;, you recommended use
    812814                of the Windows NT4 Server Manager (part of the <code class="filename">SRVTOOLS.EXE</code>) utility. Why
    813815                have you mentioned only the use of the Windows 200x/XP MMC Computer Management utility?
    814                 </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2616006"></a><a class="indexterm" name="id2616013"></a>
     816                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p><a class="indexterm" name="id2616015"></a><a class="indexterm" name="id2616023"></a>
    815817                Either tool can be used with equal effect. There is no benefit of one over the other, except that
    816818                the MMC utility is present on all Windows 200x/XP systems and does not require additional software
     
    818820                Samba-controlled domain, the only tool that permits that is the NT4 Domain User Manager, which
    819821                is provided as part of the <code class="filename">SRVTOOLS.EXE</code> utility.
    820                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2616039"></a><a name="id2616041"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2616044"></a><a class="indexterm" name="id2616052"></a><a class="indexterm" name="id2616060"></a>
     822                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2616048"></a><a name="id2616051"></a></td><td align="left" valign="top"><p><a class="indexterm" name="id2616054"></a><a class="indexterm" name="id2616062"></a><a class="indexterm" name="id2616070"></a>
    821823                I tried to set <em class="parameter"><code>valid users = @Engineers</code></em>, but it does not work. My Samba
    822824                server is an Active Directory domain member server. Has this been fixed now?
  • branches/samba-3.2.x/docs/htmldocs/Samba3-ByExample/primer.html

    r231 r272  
    1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 16. Networking Primer</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"><link rel="next" href="apa.html" title="Appendix A.  GNU General Public License version 3"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 16. Networking Primer</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="primer"></a>Chapter 16. Networking Primer</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="primer.html#id2625407">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625568">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625629">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625745">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625871">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627019">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627521">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628089">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628204">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></div><p>
     1<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 16. Networking Primer</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"><link rel="home" href="index.html" title="Samba-3 by Example"><link rel="up" href="RefSection.html" title="Part III. Reference Section"><link rel="prev" href="appendix.html" title="Chapter 15. A Collection of Useful Tidbits"><link rel="next" href="apa.html" title="Appendix A.  GNU General Public License version 3"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 16. Networking Primer</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><th width="60%" align="center">Part III. Reference Section</th><td width="20%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="primer"></a>Chapter 16. Networking Primer</h2></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="primer.html#id2625430">Requirements and Notes</a></span></dt><dt><span class="sect1"><a href="primer.html#id2625592">Introduction</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625652">Assignment Tasks</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#id2625769">Exercises</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2625894">Single-Machine Broadcast Activity</a></span></dt><dt><span class="sect2"><a href="primer.html#secondmachine">Second Machine Startup Broadcast Interaction</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627042">Simple Windows Client Connection Characteristics</a></span></dt><dt><span class="sect2"><a href="primer.html#id2627544">Windows 200x/XP Client Interaction with Samba-3</a></span></dt><dt><span class="sect2"><a href="primer.html#id2628113">Conclusions to Exercises</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01conc">Dissection and Discussion</a></span></dt><dd><dl><dt><span class="sect2"><a href="primer.html#id2628227">Technical Issues</a></span></dt></dl></dd><dt><span class="sect1"><a href="primer.html#chap01qa">Questions and Answers</a></span></dt></dl></div><p>
    22        You are about to use the equivalent of a microscope to look at the information
    33        that runs through the veins of a Windows network. We do more to observe the information than
     
    99        Samba can be configured with a minimum of complexity. Simplicity should be mastered
    1010        before you get too deeply into complexities. Let's get moving: we have work to do.
    11         </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625407"></a>Requirements and Notes</h2></div></div></div><p>
     11        </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625430"></a>Requirements and Notes</h2></div></div></div><p>
    1212        Successful completion of this primer requires two Microsoft Windows 9x/Me Workstations
    1313        as well as two Microsoft Windows XP Professional Workstations, each equipped with an Ethernet
     
    1717        on a quiet network where there is no other traffic. It is best to use a dedicated hub
    1818        with only the machines under test connected at the time of the exercises.
    19         </p><p><a class="indexterm" name="id2625428"></a>
     19        </p><p><a class="indexterm" name="id2625451"></a>
    2020        Wireshark (formerly Ethereal) has become the network protocol analyzer of choice for many network administrators.
    2121        You may find more information regarding this tool from the
     
    3737        that is used to monitor traffic; this would not allow you to complete the projects.
    3838        </p></div><p>
    39         <a class="indexterm" name="id2625497"></a>
     39        <a class="indexterm" name="id2625520"></a>
    4040        Do not worry too much if you do not have access to all this equipment; network captures
    4141        from the exercises are provided on the enclosed CD-ROM. This makes it possible to dive directly
    4242        into the analytical part of the exercises if you so desire.
    43         </p><p><a class="indexterm" name="id2625513"></a><a class="indexterm" name="id2625524"></a>
     43        </p><p><a class="indexterm" name="id2625536"></a><a class="indexterm" name="id2625547"></a>
    4444        Please do not be alarmed at the use of a high-powered analysis tool (Wireshark) in this
    4545        primer.  We expose you only to a minimum of detail necessary to complete
     
    5555        <a class="link" href="primer.html#chap01qa" title="Questions and Answers">&#8220;Questions and Answers&#8221;</a> also provides useful information
    5656        that may help you to avoid significantly time-consuming networking problems.
    57         </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625568"></a>Introduction</h2></div></div></div><p>
     57        </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625592"></a>Introduction</h2></div></div></div><p>
    5858        The purpose of this chapter is to create familiarity with key aspects of Microsoft Windows
    5959        network computing. If you want a solid technical grounding, do not gloss over these exercises.
    6060        The points covered are recurrent issues on the Samba mailing lists.
    61         </p><p><a class="indexterm" name="id2625583"></a>
     61        </p><p><a class="indexterm" name="id2625606"></a>
    6262        You can see from these exercises that Windows networking involves quite a lot of network
    6363        broadcast traffic. You can look into the contents of some packets, but only to see
     
    7575        Edition</em></span> (TOSHARG2) Chapter 9, &#8220;<span class="quote">Network Browsing,</span>&#8221; and Chapter 3,
    7676        &#8220;<span class="quote">Server Types and Security Modes.</span>&#8221;
    77         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625629"></a>Assignment Tasks</h3></div></div></div><p><a class="indexterm" name="id2625636"></a>
     77        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625652"></a>Assignment Tasks</h3></div></div></div><p><a class="indexterm" name="id2625659"></a>
    7878                You are about to witness how Microsoft Windows computer networking functions. The
    7979                exercises step through identification of how a client machine establishes a
     
    8181                each other (i.e., how browsing works) and how the two key types of user identification
    8282                (share mode security and user mode security) are affected.
    83                 </p><p><a class="indexterm" name="id2625653"></a>
     83                </p><p><a class="indexterm" name="id2625676"></a>
    8484                The networking protocols used by MS Windows networking when working with Samba
    8585                use TCP/IP as the transport protocol. The protocols that are specific to Windows
    8686                networking are encapsulated in TCP/IP. The network analyzer we use (Wireshark)
    8787                is able to show you the contents of the TCP/IP packets (or messages).
    88                 </p><div class="procedure"><a name="chap01tasks"></a><p class="title"><b>Procedure 16.1. Diagnostic Tasks</b></p><ol type="1"><li><p><a class="indexterm" name="id2625686"></a><a class="indexterm" name="id2625697"></a><a class="indexterm" name="id2625705"></a>
     88                </p><div class="procedure"><a name="chap01tasks"></a><p class="title"><b>Procedure 16.1. Diagnostic Tasks</b></p><ol type="1"><li><p><a class="indexterm" name="id2625709"></a><a class="indexterm" name="id2625720"></a><a class="indexterm" name="id2625728"></a>
    8989                        Examine network traces to witness SMB broadcasts, host announcements,
    9090                        and name resolution processes.
     
    9696                        Review traces of network logons for a Windows 9x/Me client as well as
    9797                        a domain logon for a Windows XP Professional client.
    98                         </p></li></ol></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625745"></a>Exercises</h2></div></div></div><p>
    99         <a class="indexterm" name="id2625753"></a>
     98                        </p></li></ol></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2625769"></a>Exercises</h2></div></div></div><p>
     99        <a class="indexterm" name="id2625776"></a>
    100100        You are embarking on a course of discovery. The first part of the exercise requires
    101101        two MS Windows 9x/Me systems. We called one machine <code class="constant">WINEPRESSME</code> and the
     
    112112        Choose a workgroup name (MIDEARTH) for each exercise.
    113113        </p><p>
    114         <a class="indexterm" name="id2625842"></a>
     114        <a class="indexterm" name="id2625866"></a>
    115115        The network captures provided on the CD-ROM included with this book were captured using <code class="constant">Ethereal</code>
    116116        version <code class="literal">0.10.6</code>. A later version suffices without problems (i.e. you should be using Wireshark), but an earlier version may not
     
    120120        that can be derived from this book really does warrant your taking sufficient time to practice each exercise with
    121121        care and attention to detail.
    122         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625871"></a>Single-Machine Broadcast Activity</h3></div></div></div><p>
     122        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2625894"></a>Single-Machine Broadcast Activity</h3></div></div></div><p>
    123123        In this section, we start a single Windows 9x/Me machine, then monitor network activity for 30 minutes.
    124         </p><div class="procedure"><a name="id2625882"></a><p class="title"><b>Procedure 16.2. Monitoring Windows 9x Steps</b></p><ol type="1"><li><p>
     124        </p><div class="procedure"><a name="id2625906"></a><p class="title"><b>Procedure 16.2. Monitoring Windows 9x Steps</b></p><ol type="1"><li><p>
    125125                Start the machine from which network activity will be monitored (using <code class="literal">Wireshark</code>).
    126126                Launch <code class="literal">Wireshark</code>, click
     
    139139                Analyze the capture. Identify each discrete message type that was captured. Note what transport protocol
    140140                was used. Identify the timing between messages of identical types.
    141                 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2626005"></a>Findings</h4></div></div></div><p>
     141                </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2626028"></a>Findings</h4></div></div></div><p>
    142142                The summary of the first 10 minutes of the packet capture should look like <a class="link" href="primer.html#pktcap01" title="Figure 16.1. Windows Me Broadcasts The First 10 Minutes">&#8220;Windows Me  Broadcasts  The First 10 Minutes&#8221;</a>.
    143143                A screenshot of a later stage of the same capture is shown in <a class="link" href="primer.html#pktcap02" title="Figure 16.2. Windows Me Later Broadcast Sample">&#8220;Windows Me  Later Broadcast Sample&#8221;</a>.
    144                 </p><div class="figure"><a name="pktcap01"></a><p class="title"><b>Figure 16.1. Windows Me  Broadcasts  The First 10 Minutes</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture.png" width="216" alt="Windows Me Broadcasts The First 10 Minutes"></div></div></div><br class="figure-break"><div class="figure"><a name="pktcap02"></a><p class="title"><b>Figure 16.2. Windows Me  Later Broadcast Sample</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture2.png" width="226.8" alt="Windows Me Later Broadcast Sample"></div></div></div><br class="figure-break"><p><a class="indexterm" name="id2626122"></a><a class="indexterm" name="id2626134"></a>
     144                </p><div class="figure"><a name="pktcap01"></a><p class="title"><b>Figure 16.1. Windows Me  Broadcasts  The First 10 Minutes</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture.png" width="216" alt="Windows Me Broadcasts The First 10 Minutes"></div></div></div><br class="figure-break"><div class="figure"><a name="pktcap02"></a><p class="title"><b>Figure 16.2. Windows Me  Later Broadcast Sample</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WINREPRESSME-Capture2.png" width="226.8" alt="Windows Me Later Broadcast Sample"></div></div></div><br class="figure-break"><p><a class="indexterm" name="id2626145"></a><a class="indexterm" name="id2626157"></a>
    145145                Broadcast messages observed are shown in <a class="link" href="primer.html#capsstats01" title="Table 16.1. Windows Me Startup Broadcast Capture Statistics">&#8220;Windows Me  Startup Broadcast Capture Statistics&#8221;</a>.
    146146                Actual observations vary a little, but not by much.
     
    148148                first to ensure that its name would not result in a name clash, and second to establish its
    149149                presence with the Local Master Browser (LMB).
    150                 </p><div class="table"><a name="capsstats01"></a><p class="title"><b>Table 16.1. Windows Me  Startup Broadcast Capture Statistics</b></p><div class="table-contents"><table summary="Windows Me  Startup Broadcast Capture Statistics" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="left"></colgroup><thead><tr><th align="left">Message</th><th align="center">Type</th><th align="center">Num</th><th align="left">Notes</th></tr></thead><tbody><tr><td align="left">WINEPRESSME&lt;00&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME&lt;03&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME&lt;20&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;00&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1d&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1e&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1b&gt;</td><td align="center">Qry</td><td align="center">84</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">__MSBROWSE__</td><td align="center">Reg</td><td align="center">8</td><td align="left">Registered after winning election to Browse Master</td></tr><tr><td align="left">JHT&lt;03&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 x 2. This is the name of the user that logged onto Windows</td></tr><tr><td align="left">Host Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">2</td><td align="left">Observed at 10 sec</td></tr><tr><td align="left">Domain/Workgroup Announcement MIDEARTH</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Local Master Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Get Backup List Request</td><td align="center">Qry</td><td align="center">12</td><td align="left">6 x 2 early in startup, 0.5 sec apart</td></tr><tr><td align="left">Browser Election Request</td><td align="center">Ann</td><td align="center">10</td><td align="left">5 x 2 early in startup</td></tr><tr><td align="left">Request Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">4</td><td align="left">Early in startup</td></tr></tbody></table></div></div><br class="table-break"><p><a class="indexterm" name="id2626480"></a><a class="indexterm" name="id2626488"></a>
     150                </p><div class="table"><a name="capsstats01"></a><p class="title"><b>Table 16.1. Windows Me  Startup Broadcast Capture Statistics</b></p><div class="table-contents"><table summary="Windows Me  Startup Broadcast Capture Statistics" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="left"></colgroup><thead><tr><th align="left">Message</th><th align="center">Type</th><th align="center">Num</th><th align="left">Notes</th></tr></thead><tbody><tr><td align="left">WINEPRESSME&lt;00&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME&lt;03&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">WINEPRESSME&lt;20&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;00&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1d&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1e&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1b&gt;</td><td align="center">Qry</td><td align="center">84</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">__MSBROWSE__</td><td align="center">Reg</td><td align="center">8</td><td align="left">Registered after winning election to Browse Master</td></tr><tr><td align="left">JHT&lt;03&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 x 2. This is the name of the user that logged onto Windows</td></tr><tr><td align="left">Host Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">2</td><td align="left">Observed at 10 sec</td></tr><tr><td align="left">Domain/Workgroup Announcement MIDEARTH</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Local Master Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">18</td><td align="left">300 sec apart at stable operation</td></tr><tr><td align="left">Get Backup List Request</td><td align="center">Qry</td><td align="center">12</td><td align="left">6 x 2 early in startup, 0.5 sec apart</td></tr><tr><td align="left">Browser Election Request</td><td align="center">Ann</td><td align="center">10</td><td align="left">5 x 2 early in startup</td></tr><tr><td align="left">Request Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">4</td><td align="left">Early in startup</td></tr></tbody></table></div></div><br class="table-break"><p><a class="indexterm" name="id2626504"></a><a class="indexterm" name="id2626512"></a>
    151151                From the packet trace, it should be noted that no messages were propagated over TCP/IP;
    152152                all messages employed UDP/IP.  When steady-state operation has been achieved, there is a cycle
    153153                of various announcements, re-election of a browse master, and name queries. These create
    154154                the symphony of announcements by which network browsing is made possible.
    155                 </p><p><a class="indexterm" name="id2626506"></a>
     155                </p><p><a class="indexterm" name="id2626529"></a>
    156156                For detailed information regarding the precise behavior of the CIFS/SMB protocols,
    157157                refer to the book &#8220;<span class="quote">Implementing CIFS: The Common Internet File System,</span>&#8221;
     
    160160        At this time, the machine you used to capture the single-system startup trace should still be running.
    161161        The objective of this task is to identify the interaction of two machines in respect to broadcast activity.
    162         </p><div class="procedure"><a name="id2626542"></a><p class="title"><b>Procedure 16.3. Monitoring of Second Machine Activity</b></p><ol type="1"><li><p>
     162        </p><div class="procedure"><a name="id2626565"></a><p class="title"><b>Procedure 16.3. Monitoring of Second Machine Activity</b></p><ol type="1"><li><p>
    163163                On the machine from which network activity will be monitored (using <code class="literal">Wireshark</code>),
    164164                launch <code class="literal">Wireshark</code> and click
     
    177177                Analyze the capture trace, taking note of the transport protocols used, the types of messages observed,
    178178                and what interaction took place between the two machines. Leave both machines running for the next task.
    179                 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2626658"></a>Findings</h4></div></div></div><p>
     179                </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2626681"></a>Findings</h4></div></div></div><p>
    180180                <a class="link" href="primer.html#capsstats02" title="Table 16.2. Second Machine (Windows 98) Capture Statistics">&#8220;Second Machine (Windows 98)  Capture Statistics&#8221;</a> summarizes capture statistics observed. As in the previous case,
    181181                all announcements used UDP/IP broadcasts. Also, as was observed with the last example, the second
     
    185185                &#8220;<span class="quote">Implementing CIFS: The Common Internet File System.</span>&#8221;
    186186                </p><div class="table"><a name="capsstats02"></a><p class="title"><b>Table 16.2. Second Machine (Windows 98)  Capture Statistics</b></p><div class="table-contents"><table summary="Second Machine (Windows 98)  Capture Statistics" border="1"><colgroup><col align="left"><col align="center"><col align="center"><col align="left"></colgroup><thead><tr><th align="left">Message</th><th align="center">Type</th><th align="center">Num</th><th align="left">Notes</th></tr></thead><tbody><tr><td align="left">MILGATE98&lt;00&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">MILGATE98&lt;03&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.6 sec apart</td></tr><tr><td align="left">MILGATE98&lt;20&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;00&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1d&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1e&gt;</td><td align="center">Reg</td><td align="center">8</td><td align="left">4 lots of 2, 0.75 sec apart</td></tr><tr><td align="left">MIDEARTH&lt;1b&gt;</td><td align="center">Qry</td><td align="center">18</td><td align="left">900 sec apart at stable operation</td></tr><tr><td align="left">JHT&lt;03&gt;</td><td align="center">Reg</td><td align="center">2</td><td align="left">This is the name of the user that logged onto Windows</td></tr><tr><td align="left">Host Announcement MILGATE98</td><td align="center">Ann</td><td align="center">14</td><td align="left">Every 120 sec</td></tr><tr><td align="left">Domain/Workgroup Announcement MIDEARTH</td><td align="center">Ann</td><td align="center">6</td><td align="left">900 sec apart at stable operation</td></tr><tr><td align="left">Local Master Announcement WINEPRESSME</td><td align="center">Ann</td><td align="center">6</td><td align="left">Insufficient detail to determine frequency</td></tr></tbody></table></div></div><br class="table-break"><p>
    187                 <a class="indexterm" name="id2626940"></a>
    188                 <a class="indexterm" name="id2626947"></a>
    189                 <a class="indexterm" name="id2626954"></a>
     187                <a class="indexterm" name="id2626964"></a>
     188                <a class="indexterm" name="id2626971"></a>
     189                <a class="indexterm" name="id2626978"></a>
    190190                Observation of the contents of Host Announcements, Domain/Workgroup Announcements,
    191191                and Local Master Announcements is instructive. These messages convey a significant
    192192                level of detail regarding the nature of each machine that is on the network. An example
    193193                dissection of a Host Announcement is given in <a class="link" href="primer.html#hostannounce" title="Figure 16.3. Typical Windows 9x/Me Host Announcement">&#8220;Typical Windows 9x/Me Host Announcement&#8221;</a>.
    194                 </p><div class="figure"><a name="hostannounce"></a><p class="title"><b>Figure 16.3. Typical Windows 9x/Me Host Announcement</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/HostAnnouncment.png" width="221.4" alt="Typical Windows 9x/Me Host Announcement"></div></div></div><br class="figure-break"></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2627019"></a>Simple Windows Client Connection Characteristics</h3></div></div></div><p>
     194                </p><div class="figure"><a name="hostannounce"></a><p class="title"><b>Figure 16.3. Typical Windows 9x/Me Host Announcement</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/HostAnnouncment.png" width="221.4" alt="Typical Windows 9x/Me Host Announcement"></div></div></div><br class="figure-break"></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2627042"></a>Simple Windows Client Connection Characteristics</h3></div></div></div><p>
    195195        The purpose of this exercise is to discover how Microsoft Windows clients create (establish)
    196196        connections with remote servers. The methodology involves analysis of a key aspect of how
    197197        Windows clients access remote servers: the session setup protocol.
    198         </p><div class="procedure"><a name="id2627033"></a><p class="title"><b>Procedure 16.4. Client Connection Exploration Steps</b></p><ol type="1"><li><p>
     198        </p><div class="procedure"><a name="id2627056"></a><p class="title"><b>Procedure 16.4. Client Connection Exploration Steps</b></p><ol type="1"><li><p>
    199199                Configure a Windows 9x/Me machine (MILGATE98) with a share called <code class="constant">Stuff</code>.
    200200                Create a <em class="parameter"><code>Full Access</code></em> control password on this share.
     
    217217                Save the captured data in case it is needed for later analysis.
    218218                </p></li><li><p>
    219                 <a class="indexterm" name="id2627164"></a>
     219                <a class="indexterm" name="id2627187"></a>
    220220                From the top of the packets captured, scan down to locate the first packet that has
    221221                interpreted as <code class="constant">Session Setup AndX, User: anonymous; Tree Connect AndX,
    222222                Path: \\MILGATE98\IPC$</code>.
    223                 </p></li><li><p><a class="indexterm" name="id2627183"></a><a class="indexterm" name="id2627191"></a>
     223                </p></li><li><p><a class="indexterm" name="id2627206"></a><a class="indexterm" name="id2627214"></a>
    224224                In the dissection (analysis) panel, expand the <code class="constant">SMB, Session Setup AndX Request,
    225225                and Tree Connect AndX Request</code>. Examine both operations. Identify the name of
     
    231231                that was targeted at the <code class="constant">\\MILGATE98\IPC$</code> service.
    232232                </p></li><li><p>
    233                 <a class="indexterm" name="id2627236"></a>
    234                 <a class="indexterm" name="id2627242"></a>
     233                <a class="indexterm" name="id2627259"></a>
     234                <a class="indexterm" name="id2627266"></a>
    235235                Dissect this packet as per the previous one. This packet should have a password length
    236236                of 24 (characters) and should have a password field, the contents of which is a
    237237                long hexadecimal number. Observe the name in the Account field. This is a User Mode
    238238                session setup packet.
    239                 </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2627256"></a>Findings and Comments</h4></div></div></div><p>
    240                 <a class="indexterm" name="id2627265"></a>
    241                 The <code class="constant">IPC$</code> share serves a vital purpose<sup>[<a name="id2627276" href="#ftn.id2627276" class="footnote">15</a>]</sup>
     239                </p></li></ol></div><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2627280"></a>Findings and Comments</h4></div></div></div><p>
     240                <a class="indexterm" name="id2627288"></a>
     241                The <code class="constant">IPC$</code> share serves a vital purpose<sup>[<a name="id2627299" href="#ftn.id2627299" class="footnote">15</a>]</sup>
    242242                in SMB/CIFS-based networking.  A Windows client connects to this resource to obtain the list of
    243243                resources that are available on the server. The server responds with the shares and print queues that
     
    245245                username and a <code class="constant">NULL</code> password.
    246246                </p><p>
    247                 <a class="indexterm" name="id2627296"></a>
     247                <a class="indexterm" name="id2627320"></a>
    248248                The two packets examined are material evidence of how Windows clients may
    249249                interoperate with Samba. Samba requires every connection setup to be authenticated using
     
    252252                account.
    253253                </p><p>
    254             <a class="indexterm" name="id2627316"></a><a class="indexterm" name="id2627322"></a>
    255             <a class="indexterm" name="id2627331"></a>
     254            <a class="indexterm" name="id2627339"></a><a class="indexterm" name="id2627345"></a>
     255            <a class="indexterm" name="id2627354"></a>
    256256                Samba has a special name for the <code class="constant">NULL</code>, or empty, user account:
    257257                it calls it the <a class="link" href="smb.conf.5.html#GUESTACCOUNT" target="_top">guest account</a>. The
     
    262262                <a class="link" href="primer.html#nullconnect" title="Figure 16.4. Typical Windows 9x/Me NULL SessionSetUp AndX Request">&#8220;Typical Windows 9x/Me NULL SessionSetUp AndX Request&#8221;</a>.
    263263                </p><div class="figure"><a name="nullconnect"></a><p class="title"><b>Figure 16.4. Typical Windows 9x/Me NULL SessionSetUp AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/NullConnect.png" width="221.4" alt="Typical Windows 9x/Me NULL SessionSetUp AndX Request"></div></div></div><br class="figure-break"><p>
    264                 <a class="indexterm" name="id2627416"></a>
    265                 <a class="indexterm" name="id2627423"></a>
    266                 <a class="indexterm" name="id2627430"></a>
     264                <a class="indexterm" name="id2627439"></a>
     265                <a class="indexterm" name="id2627446"></a>
     266                <a class="indexterm" name="id2627453"></a>
    267267                When a UNIX/Linux system does not have a <code class="constant">nobody</code> user account
    268268                (<code class="filename">/etc/passwd</code>), the operation of the <code class="constant">NULL</code>
     
    272272                is shown in <a class="link" href="primer.html#userconnect" title="Figure 16.5. Typical Windows 9x/Me User SessionSetUp AndX Request">&#8220;Typical Windows 9x/Me User SessionSetUp AndX Request&#8221;</a>.
    273273                </p><div class="figure"><a name="userconnect"></a><p class="title"><b>Figure 16.5. Typical Windows 9x/Me User SessionSetUp AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/UserConnect.png" width="221.4" alt="Typical Windows 9x/Me User SessionSetUp AndX Request"></div></div></div><br class="figure-break"><p>
    274                 <a class="indexterm" name="id2627507"></a>
     274                <a class="indexterm" name="id2627530"></a>
    275275                The User Mode connection packet contains the account name and the domain name.
    276276                The password is provided in Microsoft encrypted form, and its length is shown
    277277                as 24 characters. This is the length of Microsoft encrypted passwords.
    278                 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2627521"></a>Windows 200x/XP Client Interaction with Samba-3</h3></div></div></div><p>
     278                </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2627544"></a>Windows 200x/XP Client Interaction with Samba-3</h3></div></div></div><p>
    279279        By now you may be asking, &#8220;<span class="quote">Why did you choose to work with Windows 9x/Me?</span>&#8221;
    280280        </p><p>
     
    291291        a domain member of either a Samba-controlled domain or a Windows NT4 or 200x Active Directory domain.
    292292        Here we do not provide details for how to configure this, as full coverage is provided earlier in this book.
    293         </p><div class="procedure"><a name="id2627564"></a><p class="title"><b>Procedure 16.5. Steps to Explore Windows XP Pro Connection Set-up</b></p><ol type="1"><li><p>
     293        </p><div class="procedure"><a name="id2627587"></a><p class="title"><b>Procedure 16.5. Steps to Explore Windows XP Pro Connection Set-up</b></p><ol type="1"><li><p>
    294294                Start your domain controller. Also, start the Wireshark monitoring machine, launch Wireshark,
    295295                and then wait for the next step to complete.
     
    320320                in this chapter.
    321321                </p></li><li><p>
    322                 <a class="indexterm" name="id2627790"></a>
    323                 <a class="indexterm" name="id2627797"></a>
     322                <a class="indexterm" name="id2627813"></a>
     323                <a class="indexterm" name="id2627820"></a>
    324324                From the top of the packets captured, scan down to locate the first packet that has
    325325                interpreted as <code class="constant">Session Setup AndX Request, NTLMSSP_AUTH</code>.
    326326                </p></li><li><p>
    327                 <a class="indexterm" name="id2627817"></a>
    328                 <a class="indexterm" name="id2627824"></a>
    329                 <a class="indexterm" name="id2627831"></a>
     327                <a class="indexterm" name="id2627840"></a>
     328                <a class="indexterm" name="id2627847"></a>
     329                <a class="indexterm" name="id2627854"></a>
    330330                In the dissection (analysis) panel, expand the <code class="constant">SMB, Session Setup AndX Request</code>.
    331331                Expand the packet decode information, beginning at the <code class="constant">Security Blob:</code>
     
    339339                has been decoded as <code class="constant">Session Setup AndX Request, NTLMSSP_AUTH</code>.
    340340                </p></li><li><p>
    341                 <a class="indexterm" name="id2627893"></a>
     341                <a class="indexterm" name="id2627917"></a>
    342342                In the dissection (analysis) panel, expand the <code class="constant">SMB, Session Setup AndX Request</code>.
    343343                Expand the packet decode information, beginning at the <code class="constant">Security Blob:</code>
     
    350350                password and then the NT (case-preserving) password hash.
    351351                </p></li><li><p>
    352                 <a class="indexterm" name="id2627955"></a>
    353                 <a class="indexterm" name="id2627962"></a>
     352                <a class="indexterm" name="id2627978"></a>
     353                <a class="indexterm" name="id2627985"></a>
    354354                The passwords are 24-character hexadecimal numbers. This packet confirms that this is a User Mode
    355355                session setup packet.
    356                 </p></li></ol></div><div class="figure"><a name="XPCap01"></a><p class="title"><b>Figure 16.6. Typical Windows XP NULL Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-NullConnection.png" width="270" alt="Typical Windows XP NULL Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="figure"><a name="XPCap02"></a><p class="title"><b>Figure 16.7. Typical Windows XP User Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-UserConnection.png" width="270" alt="Typical Windows XP User Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2628058"></a>Discussion</h4></div></div></div><p><a class="indexterm" name="id2628065"></a>
     356                </p></li></ol></div><div class="figure"><a name="XPCap01"></a><p class="title"><b>Figure 16.6. Typical Windows XP NULL Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-NullConnection.png" width="270" alt="Typical Windows XP NULL Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="figure"><a name="XPCap02"></a><p class="title"><b>Figure 16.7. Typical Windows XP User Session Setup AndX Request</b></p><div class="figure-contents"><div class="mediaobject"><img src="images/WindowsXP-UserConnection.png" width="270" alt="Typical Windows XP User Session Setup AndX Request"></div></div></div><br class="figure-break"><div class="sect3" lang="en"><div class="titlepage"><div><div><h4 class="title"><a name="id2628081"></a>Discussion</h4></div></div></div><p><a class="indexterm" name="id2628088"></a>
    357357                This exercise demonstrates that, while the specific protocol for the Session Setup AndX is handled
    358358                in a more sophisticated manner by recent MS Windows clients, the underlying rules or principles
     
    361361                technology server (one using Windows NT4/200x or Samba). It also demonstrates that an authenticated
    362362                connection must be made before resources can be used.
    363                 </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2628089"></a>Conclusions to Exercises</h3></div></div></div><p>
     363                </p></div></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2628113"></a>Conclusions to Exercises</h3></div></div></div><p>
    364364        In summary, the following points have been established in this chapter:
    365365        </p><div class="itemizedlist"><ul type="disc"><li><p>
     
    380380                databases in concurrent deployment. Refer to <span class="emphasis"><em>TOSHARG2</em></span>, Chapter 10, &#8220;<span class="quote">Account Information Databases.</span>&#8221;
    381381                </p></li></ul></div></div></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="chap01conc"></a>Dissection and Discussion</h2></div></div></div><p>
    382         <a class="indexterm" name="id2628177"></a>
     382        <a class="indexterm" name="id2628200"></a>
    383383        The exercises demonstrate the use of the <code class="constant">guest</code> account, the way that
    384384        MS Windows clients and servers resolve computer names to a TCP/IP address, and how connections
     
    388388        the Microsoft knowledgebase article
    389389        <a class="ulink" href="http://support.microsoft.com/support/kb/articles/Q102/78/8.asp" target="_top">Q102878.</a>
    390         </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2628204"></a>Technical Issues</h3></div></div></div><p>
    391                 <a class="indexterm" name="id2628212"></a>
     390        </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2628227"></a>Technical Issues</h3></div></div></div><p>
     391                <a class="indexterm" name="id2628235"></a>
    392392                Network browsing involves SMB broadcast announcements, SMB enumeration requests,
    393393                connections to the <code class="constant">IPC$</code> share, share enumerations, and SMB connection
     
    397397        The questions and answers given in this section are designed to highlight important aspects of Microsoft
    398398        Windows networking.
    399         </p><div class="qandaset"><dl><dt> <a href="primer.html#id2628258">
     399        </p><div class="qandaset"><dl><dt> <a href="primer.html#id2628281">
    400400                What is the significance of the MIDEARTH&lt;1b&gt; type query?
    401                 </a></dt><dt> <a href="primer.html#id2628304">
     401                </a></dt><dt> <a href="primer.html#id2628328">
    402402                What is the significance of the MIDEARTH&lt;1d&gt; type name registration?
    403                 </a></dt><dt> <a href="primer.html#id2628378">
     403                </a></dt><dt> <a href="primer.html#id2628402">
    404404                What is the role and significance of the &lt;01&gt;&lt;02&gt;__MSBROWSE__&lt;02&gt;&lt;01&gt;
    405405                name registration?
    406                 </a></dt><dt> <a href="primer.html#id2628411">
     406                </a></dt><dt> <a href="primer.html#id2628434">
    407407                What is the significance of the MIDEARTH&lt;1e&gt; type name registration?
    408                 </a></dt><dt> <a href="primer.html#id2628442">
     408                </a></dt><dt> <a href="primer.html#id2628465">
    409409               
    410410                What is the significance of the guest account in smb.conf?
    411                 </a></dt><dt> <a href="primer.html#id2628520">
     411                </a></dt><dt> <a href="primer.html#id2628543">
    412412                Is it possible to reduce network broadcast activity with Samba-3?
    413                 </a></dt><dt> <a href="primer.html#id2628629">
     413                </a></dt><dt> <a href="primer.html#id2628652">
    414414                Can I just use plain-text passwords with Samba?
    415                 </a></dt><dt> <a href="primer.html#id2628716">
     415                </a></dt><dt> <a href="primer.html#id2628739">
    416416                What parameter in the smb.conf file is used to enable the use of encrypted passwords?
    417                 </a></dt><dt> <a href="primer.html#id2628757">
     417                </a></dt><dt> <a href="primer.html#id2628780">
    418418                Is it necessary to specify encrypt passwords = Yes
    419419                when Samba-3 is configured as a domain member?
    420                 </a></dt><dt> <a href="primer.html#id2628789">
     420                </a></dt><dt> <a href="primer.html#id2628812">
    421421                Is it necessary to specify a guest account when Samba-3 is configured
    422422                as a domain member server?
    423                 </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2628258"></a><a name="id2628260"></a></td><td align="left" valign="top"><p>
     423                </a></dt></dl><table border="0" summary="Q and A Set"><col align="left" width="1%"><tbody><tr class="question"><td align="left" valign="top"><a name="id2628281"></a><a name="id2628283"></a></td><td align="left" valign="top"><p>
    424424                What is the significance of the MIDEARTH&lt;1b&gt; type query?
    425425                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    426                 <a class="indexterm" name="id2628272"></a>
    427                 <a class="indexterm" name="id2628282"></a>
     426                <a class="indexterm" name="id2628296"></a>
     427                <a class="indexterm" name="id2628305"></a>
    428428                This is a broadcast announcement by which the Windows machine is attempting to
    429429                locate a Domain Master Browser (DMB) in the event that it might exist on the network.
    430430                Refer to <span class="emphasis"><em>TOSHARG2,</em></span> Chapter 9, Section 9.7, &#8220;<span class="quote">Technical Overview of Browsing,</span>&#8221;
    431431                for details regarding the function of the DMB and its role in network browsing.
    432                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628304"></a><a name="id2628306"></a></td><td align="left" valign="top"><p>
     432                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628328"></a><a name="id2628330"></a></td><td align="left" valign="top"><p>
    433433                What is the significance of the MIDEARTH&lt;1d&gt; type name registration?
    434434                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    435                 <a class="indexterm" name="id2628319"></a>
    436                 <a class="indexterm" name="id2628328"></a>
     435                <a class="indexterm" name="id2628342"></a>
     436                <a class="indexterm" name="id2628351"></a>
    437437                This name registration records the machine IP addresses of the LMBs.
    438438                Network clients can query this name type to obtain a list of browser servers from the
     
    452452                        </p></li><li><p>
    453453                        The IP address of the LMB on the local segment
    454                         </p></li></ul></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628378"></a><a name="id2628381"></a></td><td align="left" valign="top"><p>
     454                        </p></li></ul></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628402"></a><a name="id2628404"></a></td><td align="left" valign="top"><p>
    455455                What is the role and significance of the &lt;01&gt;&lt;02&gt;__MSBROWSE__&lt;02&gt;&lt;01&gt;
    456456                name registration?
    457457                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    458                 <a class="indexterm" name="id2628396"></a>
     458                <a class="indexterm" name="id2628419"></a>
    459459                This name is registered by the browse master to broadcast and receive domain announcements.
    460460                Its scope is limited to the local network segment, or subnet. By querying this name type,
    461461                master browsers on networks that have multiple domains can find the names of master browsers
    462462                for each domain.
    463                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628411"></a><a name="id2628413"></a></td><td align="left" valign="top"><p>
     463                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628434"></a><a name="id2628436"></a></td><td align="left" valign="top"><p>
    464464                What is the significance of the MIDEARTH&lt;1e&gt; type name registration?
    465465                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    466                 <a class="indexterm" name="id2628425"></a>
     466                <a class="indexterm" name="id2628449"></a>
    467467                This name is registered by all browse masters in a domain or workgroup. The registration
    468468                name type is known as the Browser Election Service. Master browsers register themselves
    469469                with this name type so that DMBs can locate them to perform cross-subnet
    470470                browse list updates. This name type is also used to initiate elections for Master Browsers.
    471                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628442"></a><a name="id2628444"></a></td><td align="left" valign="top"><p>
    472                 <a class="indexterm" name="id2628448"></a>
     471                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628465"></a><a name="id2628467"></a></td><td align="left" valign="top"><p>
     472                <a class="indexterm" name="id2628471"></a>
    473473                What is the significance of the <em class="parameter"><code>guest account</code></em> in smb.conf?
    474474                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
     
    483483                or there must be an entry in the <code class="filename">smb.conf</code> file with a valid UNIX account, such as
    484484                <a class="link" href="smb.conf.5.html#GUESTACCOUNT" target="_top">guest account = ftp</a>.
    485                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628520"></a><a name="id2628522"></a></td><td align="left" valign="top"><p>
     485                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628543"></a><a name="id2628545"></a></td><td align="left" valign="top"><p>
    486486                Is it possible to reduce network broadcast activity with Samba-3?
    487487                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    488                 <a class="indexterm" name="id2628534"></a>
    489                 <a class="indexterm" name="id2628540"></a>
     488                <a class="indexterm" name="id2628557"></a>
     489                <a class="indexterm" name="id2628564"></a>
    490490                Yes, there are two ways to do this. The first involves use of WINS (See <span class="emphasis"><em>TOSHARG2</em></span>, Chapter 9,
    491491                Section 9.5, &#8220;<span class="quote">WINS  The Windows Inter-networking Name Server</span>&#8221;); the
     
    493493                a correctly configured DNS server (see <span class="emphasis"><em>TOSHARG2</em></span>, Chapter 9, Section 9.3, &#8220;<span class="quote">Discussion</span>&#8221;).
    494494                </p><p>
    495                 <a class="indexterm" name="id2628572"></a>
    496                 <a class="indexterm" name="id2628579"></a>
    497                 <a class="indexterm" name="id2628588"></a>
     495                <a class="indexterm" name="id2628595"></a>
     496                <a class="indexterm" name="id2628602"></a>
     497                <a class="indexterm" name="id2628611"></a>
    498498                The use of WINS reduces network broadcast traffic. The reduction is greatest when all network
    499499                clients are configured to operate in <em class="parameter"><code>Hybrid Mode</code></em>. This can be effected through
     
    503503                Use of SMB without NetBIOS is possible only on Windows 200x/XP Professional clients and servers, as
    504504                well as with Samba-3.
    505                 </p></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628629"></a><a name="id2628631"></a></td><td align="left" valign="top"><p>
     505                </p></div></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628652"></a><a name="id2628654"></a></td><td align="left" valign="top"><p>
    506506                Can I just use plain-text passwords with Samba?
    507507                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
     
    526526                PDC/BDC to provide Windows user and group accounts, the <em class="parameter"><code>idmap uid, idmap gid</code></em> ranges
    527527                set in the <code class="filename">smb.conf</code> file provide the local UID/GIDs needed for local identity management purposes.
    528                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628716"></a><a name="id2628718"></a></td><td align="left" valign="top"><p>
     528                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628739"></a><a name="id2628741"></a></td><td align="left" valign="top"><p>
    529529                What parameter in the <code class="filename">smb.conf</code> file is used to enable the use of encrypted passwords?
    530530                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    531531                The parameter in the <code class="filename">smb.conf</code> file that controls this behavior is known as <em class="parameter"><code>encrypt
    532532                passwords</code></em>. The default setting for this in Samba-3 is <code class="constant">Yes (Enabled)</code>.
    533                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628757"></a><a name="id2628759"></a></td><td align="left" valign="top"><p>
     533                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628780"></a><a name="id2628782"></a></td><td align="left" valign="top"><p>
    534534                Is it necessary to specify <a class="link" href="smb.conf.5.html#ENCRYPTPASSWORDS" target="_top">encrypt passwords = Yes</a>
    535535                when Samba-3 is configured as a domain member?
    536536                </p></td></tr><tr class="answer"><td align="left" valign="top"></td><td align="left" valign="top"><p>
    537537                No. This is the default behavior.
    538                 </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628789"></a><a name="id2628791"></a></td><td align="left" valign="top"><p>
     538                </p></td></tr><tr class="question"><td align="left" valign="top"><a name="id2628812"></a><a name="id2628814"></a></td><td align="left" valign="top"><p>
    539539                Is it necessary to specify a <em class="parameter"><code>guest account</code></em> when Samba-3 is configured
    540540                as a domain member server?
     
    544544                necessary to provide a <a class="link" href="smb.conf.5.html#GUESTACCOUNT" target="_top">guest account = an_account</a>,
    545545                where <code class="constant">an_account</code> is a valid local UNIX user account.
    546                 </p></td></tr></tbody></table></div></div><div class="footnotes"><br><hr width="100" align="left"><div class="footnote"><p><sup>[<a name="ftn.id2627276" href="#id2627276" class="para">15</a>] </sup>TOSHARG2, Sect 4.5.1</p></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="RefSection.html">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top">Chapter 15. A Collection of Useful Tidbits </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> Appendix A. 
     546                </p></td></tr></tbody></table></div></div><div class="footnotes"><br><hr width="100" align="left"><div class="footnote"><p><sup>[<a name="ftn.id2627299" href="#id2627299" class="para">15</a>] </sup>TOSHARG2, Sect 4.5.1</p></div></div></div><div class="navfooter"><hr><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="appendix.html">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="RefSection.html">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="apa.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top">Chapter 15. A Collection of Useful Tidbits </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> Appendix A. 
    547547    GNU General Public License version 3
    548548  </td></tr></table></div></body></html>
Note: See TracChangeset for help on using the changeset viewer.