domain group and local group API needed

Gerald Carter cartegw at Eng.Auburn.EDU
Fri Oct 30 16:25:56 GMT 1998


Kyle McDonald wrote:
> 
> > >
> > > Samba servers that are members of a domain can have
> > > no concept of "Domain" groups - such a thing simply
> > > doesn't exist in UNIX.
> 
>     Yes, but an administrator MIGHT want to map one of
>     the domain groups (from the PDC for the domain samba
>     is a member of) to a unix group, right?
> 
>     Is there some better way to do this?

Don't think it would matter as the group membership is 
defined by the PDC.  The unix account is used to get 
the uid.  

But then if you mapped the  DOMAINS ADMINS group 
to some group on the unix box, that would only affect 
connections to the unix box right?

I'm just trying to think of possible security problems.
Just kind of cloudy right now.




j-
________________________________________________________________________
                            Gerald ( Jerry ) Carter	
Engineering Network Services                           Auburn University 
jerry at eng.auburn.edu             http://www.eng.auburn.edu/users/cartegw

       "...a hundred billion castaways looking for a home."
                                  - Sting "Message in a Bottle" ( 1979 )


More information about the samba-ntdom mailing list