3.0a21 and HEAD: only primary group of a domain user is set on
smbd
Andrew Bartlett
abartlet at samba.org
Wed Mar 5 21:30:45 GMT 2003
On Thu, 2003-03-06 at 08:17, Ken Cross wrote:
> >
> > Ken's patch is not required for posix users of winbind (ie
> > the NSS subsystem). It is required if you want (for a custom
> > user interface) to know all the members of a particular
> > group, but I'm not sure it's the right way to do it. (I
> > think a custom winbind command would do better).
> >
>
> I'm not being argumentative (really!), but the *main* reason for my
> patch is that it will give you consistent information whether you've
> joined an NT domain or an AD. That is, all the group members will be
> returned from WINBINDD_GETGRGID or WINBINDD_GETGRNAM either way.
So, wouldn't that mean that the 'correct' approach would be to strip
such users from the RPC groups? :-)
Andrew Bartlett
--
Andrew Bartlett abartlet at pcug.org.au
Manager, Authentication Subsystems, Samba Team abartlet at samba.org
Student Network Administrator, Hawker College abartlet at hawkerc.net
http://samba.org http://build.samba.org http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20030306/8a935c9a/attachment.bin
More information about the samba-technical
mailing list