[Samba] Samba Group Mapping

Brajesh Shrivastava brajeshkumar_shrivas at symantec.com
Mon Jan 11 04:48:06 MST 2010


Hi All

I have Samba 3.2.11 installed on Suse (sles 10) machine. I am playing 
around the group mapping functionality. When I map a linux group to nt 
group. I can see that groups is visible on windows client. But, if I 
restart the smbd daemon (while changing the scurity mode for ads to user 
or vice versa), I can no more see the mapped group to the the Windows 
client. Though, I was able to see the mapping in the output of 'net 
groupmap list' command. I will request you to please let me know the 
answer of following questions:

1. Is there any way to see the mapped group to the windows client even 
after changing the security mode or restarting the samba server?

2. Does  samba store the group mapping in group_mapping.ldb file. Will 
it be enough to copy this file to other node to get cluster wise 
solution for group mapping or do I need to follow any other steps.

3. Can I map built-in domain group like "Domain Admins", "Domain Users" 
etc to the Unix group? If yes, should I need to keep SID fixed by 
specifying rid value?

4. If I want to do the manual mapping, do I need to specify parameter 
'add group script' in smb.conf? When is this option called?


Thanks a lot in advance.


More information about the samba mailing list