do not support winbind users or groups in smb.confi without seciftying a domain

Andrew Bartlett abartlet at samba.org
Thu Nov 27 19:45:09 GMT 2003


On Fri, 2003-11-28 at 02:01, Gerald (Jerry) Carter wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Green, Paul wrote:
> | Could the testparm command check to ensure that the domain
> | has been specified?  Give the user the error message as
> | early as possible...
> 
> Not actually.  That is the crux of the problem.  We can't tell if
> 'Domain Admins' is a real unix group or if the admin meant
> 'FOO\Domain Admins'.

This is what has me confused about this issue - if we can't tell that
this is a winbind group, and if nsswitch is actually working correctly,
how is a winbind group any different from a local unix group?

I understand this means we cannot apply any 'is winbind group'
optimisations, but other than that, what is is about these groups that
causes things to break?

Andrew Bartlett

-- 
Andrew Bartlett                                 abartlet at pcug.org.au
Manager, Authentication Subsystems, Samba Team  abartlet at samba.org
Student Network Administrator, Hawker College   abartlet at hawkerc.net
http://samba.org     http://build.samba.org     http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20031128/018dd0ff/attachment.bin


More information about the samba-technical mailing list