get_domain_user_groups() improvement.

Volker.Lendecke at SerNet.DE Volker.Lendecke at SerNet.DE
Sun Oct 3 17:06:48 GMT 2004

On Fri, Sep 24, 2004 at 07:00:08AM +1000, Andrew Bartlett wrote:
> My feeling is that we can push all NSS calls that regard groups into
> such a mechanism, without difficulty.  Other calls are more marginal -
> we should look at the pointy-end (large numbers of users/groups)
> performance implications of each call.

If I understand the problem at hand correctly, this all revolves around the
lack of a nss_givemealluserswiththisprimarygid() call, right? If this is
correct, why not throw away nss_ldap and have winbind handle that. nss_ldap
can't be that complicated, and we have ldap code in winbind anyway. Then from
smbd we could scan nss with winbindd_off() and directly ask winbind for the
rest, this time with a direct and more explicit call.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: not available
Url :

More information about the samba-technical mailing list