FIxed [was Re: Authentication through transitive trusts]
Ken Cross
kcross at nssolutions.com
Thu Aug 7 11:10:01 GMT 2003
> >
> > How 'bout we add a switch to wbinfo (and appropriate support in
> > winbindd) to limit the list on -u or -g to the domain we
> have joined,
> > or some specific domain. Maybe --domain=<domain-name>
> (with something
> > like "." for the domain we joined)?
>
> why are you running 'wbinfo -u'? What purpose does it serve
> other than
> debugging? Are you piping the users to another program?
>
Yep. It's used to manage ACLs. Domain users/groups can be added to ACLs,
so we present a list and let them choose.
Consequently, we need to authenticate against any domain, but be able to
limit the list to a reasonable size.
Currently, the list from wbinfo -u is just the domain we joined or *all*
domains. Some other options would be useful.
Ken
________________________________
Ken Cross
Network Storage Solutions
Phone 865.675.4070 ext 31
kcross at nssolutions.com
More information about the samba-technical
mailing list