CVS update: samba/source/auth

Jean Francois Micouleau Jean-Francois.Micouleau at dalalu.fr
Sun Jun 29 15:21:04 GMT 2003



On 29 Jun 2003, Simo Sorce wrote:

> > Like I said before, I don't ever want winbind accessing passdb
> > information directly.  It's not what winbind is there for.
> >
> > If I'm wrong, then convince me of a real situation where
> > (a) you would want to do this, and (b) there is no other way
> > to solve the problem other than having winbind do passdb lookups.
>
> A PDC that want to use the samba passdb as the authoritative source of
> user/group information without using LDAP.
>
> nss_winbindd has the great advantage that it can be tweeked to in facts
> support global groups into local groups as a real PDC do.
> That thing cannot be done with nss_ldap.
>
> so if nss_winbind can access the passdb then it would be great.
> the esaiest way is to do it through winbind
>
> I'm open to other solutions, if any, as well.

another solution was to have winbind send a samba specific flag in the
SAMR query, and the smbd SAMR server code would check that flag before
looking up UNIX security.

I don't remember with who, I talked of that solution (maybe tridge or
jeremy).

	J.F.





More information about the samba-technical mailing list