FN 11.2 RC1 AD : show domain name/username in list, auditing and "Computer Management/System Tools"

Status
Not open for further replies.

JoeAtWork

Contributor
Joined
Aug 20, 2018
Messages
165
Hi All,

Great work on FreeNAS 11.2 RC1 and the Windows AD integration!

Info :
I have Windows server 2003 with the same old schema with trusts, old baggage and it works amazingly fine.

Issue 1:
When I try to "Change Permissions" on the dataset I first saw a few domain usernames, so I typed in "Administrator" and now I cannot get a list of local users or domain groups. In one of the example video's it showed AD/%username% and all I see is a few %username% objects in the list( Lawrence Systems "How To Setup FreeNAS 11.1 With Active Directory & Windows Server 2016"). I am able to see the domain/username now by un-checking box that says : Use Default Domain.

For most ALL shares this is fine as I always want "Administrator" and "Domain Admins" to have access and then use Windows to grant the granular access needed for the share and remove everyone from having access. Is there a bug that does not let me scroll thru a list of domain users and groups? wbinfo -u and wbinfo -g work fine from the command line.

Issue 2:
To verify my settings and make a backup to stare and compare I would like to know if I can edit/save/print the /usr/local/etc/smb.conf file or am I only allowed to edit in the gui?

Issue 3:
I want to increase logging to show info about users and computers that delete files, i.e. auditing

Issue 4:
In Windows we can use "Computer Management" to connect to a server and see the shares and users connected. When I do this with FreeNAS I get "Event viewer cannot connect to computer 'xxxxxxxxxx'. The error reported is : The RPC server is unavailable

I can still get in and see the shares and file locks, but the error would cause others to stop and not use the tool at all and say it was broken.

=========================================================

In reality I am impressed with the ease of use on this version of Samba 4.7 and the default settings are very good.

Thanks,
Joe
 

RegularJoe

Patron
Joined
Aug 19, 2013
Messages
330
I am upgrading my FreeNAS box now and will test as soon as it is done. Was the Samba upgraded beyond "Samba version 4.7.0-GIT-3eb6138eb23-FreeNAS" ?
 

JoeAtWork

Contributor
Joined
Aug 20, 2018
Messages
165
I have upgraded to : FreeNAS-11.2-RC2

Issue 1:
In the legacy GUI I pick the "Change Permissions" button, wait 20 seconds and the dialog box displays, I see existing "domain/user" but can't pick local users, I pick the group and I can only pick/see local users.
In the AJAX GUI both drop-down lists show local users/groups and NO domain users/groups at all.

FWIW
Volume : ShareX
Dataset : Windows/data
Dataset : Windows/public

wbinfo -u and wbinfo -g work fine



Issue 2:
file is /usr/local/etc/smb4.conf

if I have 127.0.0.1 checked in the legacy GUI it shows twice in the smb4.conf file
the SMB4.conf is populated with the correct workgroup/domain from the AD integration but the legacy GUI and AJAX GUI is wrong and still at WORKGROUP



Issue 3:
VFS audit or VFS extd_audit seem like they could do something but some of those are stack able and others are not, some look like they track UNIX file system changes and not what we would track on a Windows Server, i.e. domain/user deleted path/file on date/time



Issue 4:
nope and I tried it as another user that ONLY had a connection as domain/adminZZZ and they got the same error when using windows 7


The version of Samba is still : Samba version 4.7.0-GIT-c91663fe5ae-FreeNAS
 
D

dlavigne

Guest
Please report your remaining issues at bugs.freenas.org and post the issue number here.
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
I have upgraded to : FreeNAS-11.2-RC2

Issue 1:
In the legacy GUI I pick the "Change Permissions" button, wait 20 seconds and the dialog box displays, I see existing "domain/user" but can't pick local users, I pick the group and I can only pick/see local users.
In the AJAX GUI both drop-down lists show local users/groups and NO domain users/groups at all.

FWIW
Volume : ShareX
Dataset : Windows/data
Dataset : Windows/public

wbinfo -u and wbinfo -g work fine

This might be a caching issue. The dropdown is also limited to 25 entries, but should auto-complete. Try rebuilding the directory service cache.

Issue 2:
file is /usr/local/etc/smb4.conf

if I have 127.0.0.1 checked in the legacy GUI it shows twice in the smb4.conf file
I'll check on that.

the SMB4.conf is populated with the correct workgroup/domain from the AD integration but the legacy GUI and AJAX GUI is wrong and still at WORKGROUP
We actually get the workgroup for the smb4.conf by querying the DC (it's the only way to be sure that you have the right one). We weren't storing it persistently though. This changes in 11.2-U1 forward. We will retrieve from AD and store in the configuration file.


Issue 3:
VFS audit or VFS extd_audit seem like they could do something but some of those are stack able and others are not, some look like they track UNIX file system changes and not what we would track on a Windows Server, i.e. domain/user deleted path/file on date/time
We're going to pare down the list of available. vfs_full audit should do what you want once you've configured it correctly.

Issue 4:
nope and I tried it as another user that ONLY had a connection as domain/adminZZZ and they got the same error when using windows 7

What error was that?
 
Status
Not open for further replies.
Top