get_domain_user_groups() improvement.

Andrew Bartlett abartlet at
Thu Sep 23 21:00:08 GMT 2004

On Fri, 2004-09-24 at 01:14, Igor Belyi wrote:
> Gerald (Jerry) Carter wrote:
> > Andrew Bartlett wrote:
> > |> Maybe you don't care about it anymore, but those people
> > | Sorry - I didn't mean it to come across like that.  Of
> > I should have added a note that this was not a
> > personal comment.  I just want to make sure that no
> I didn't mean to stir a fight... (mwa-ha-ha!) ;o)
> Just to clarify the idea - pushing _all_ NSS calls from common pdbpass 
> functions into backends and letting ldapsam backend assume that UNIX 
> accounts and groups are in traditianal LDAP objects while keeping all 
> other backends to use NSS calls is the right approach. Is that correct?

My feeling is that we can push all NSS calls that regard groups into
such a mechanism, without difficulty.  Other calls are more marginal -
we should look at the pointy-end (large numbers of users/groups)
performance implications of each call.

Andrew Bartlett
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url :

More information about the samba-technical mailing list