D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Samba should I be concerned ?

 

On 19/04/13 18:09, Kevin Lucas wrote:
>
> Fortune smiles in the shape of 2 Win Xp machines on the NW
>
And therein lies your problem - XP has a much earlier SMB protocol level
and they also like WINS and NETBIOS, which has been deprecated as far as
reasonably possible in modern MS platforms. Modern SMB/Samba is all
about Kerberos, LDAP and DNS and your Fedora 18/Samba4 setup will be
defaulting to the newer versions. You're going to have to manually lock
everything - win and linux - to the correct levels.

Obviously I don't know how your network is setup but modern SMB/Samba is
also happier running in security=domain mode with all of the attendant
complexities and advantages: security=share/user for the simpler
workgroup/homegroup model (which I guess is what you're using) is
theoretically less complex but I can honestly say I have never even
looked at it, and nor do I know anyone else who has even bothered trying
to set it up. Surely you want a centralized box running AD if you've got
more than a couple of machines anyway, whether it's a Samba4 one or an
actual MS server instance?

Either way, I don't envy you as I think that's seriously going to be
difficult to setup properly. You're going to be upgrading or replacing
those crappy old XP boxes within the year anyway so I'd just bite the
bullet and deploy a 'proper' AD server, on Samba4 if necessary and you
can immediately switch the entire network up a SMB version or two. There
are some hideous and unfixable issues with weak NTLM on clients as old
as XP, and microsoft, probably completely fairly, don't have any
interest in patching up that old crap when even Vista has good support
and win7/8 have full support.

Regards

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq