[Samba] Issues with AD trusts and UID/GID ranges

Rowland Penny rpenny at samba.org
Thu Nov 2 19:49:57 UTC 2023


On Thu, 2 Nov 2023 15:32:38 -0400
Anthony Halliday via samba <samba at lists.samba.org> wrote:

> Hello,
> Thank you for the previous reply. This has made me realize that I
> misunderstood most of the settings that I set. To clarify, I
> currently do not have UIDs and GIDs stored in Active Directory, and I
> currently don’t plan on setting that up. My other computers are using
> tdb as the backend, and for uniformity across all my machines I would
> like to use that on all of them. Could you possibly elaborate a bit
> more on what the * range is for. I haven’t been able to find any
> useful info in the docs/wiki. Also, other than restarting samba and
> winbind, is there anything else I have to do to make the UID changes
> take effect? Thanks.

As I said, the default range '*' is meant for the Well Known SIDs
(BUILTIN etc), it is not meant for your main DOMAIN. If you have just
been using the default domain on your Unix domain members, then you are
in trouble, try reading these:

https://wiki.samba.org/index.php/Setting_up_Samba_as_a_Domain_Member

https://wiki.samba.org/index.php/Idmap_config_rid

Rowland







More information about the samba mailing list