ldap search for members of "domain users" ??

Gerald (Jerry) Carter jerry at samba.org
Fri Jul 1 16:30:48 GMT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Volker Lendecke wrote:
> Hi!
> 
> Attached find two sniffs of an attempt to enumerate 
> the group members of "Domänen-Benutzer" (-513) of a W2k3
> server. ads.cap is winbind with 'security=ads' in response
> to a 'getent group <number>' using LDAP. This only gives
> a single member.
> 
> rpc.cap is a direct 'rpcclient -c "groupmem 513"', giving a big 
> number of members.
> 
> What am I doing wrong???

Nothing.  I mentioned this at Samba XP.  Didn't you say
something about needing range retrieval to get this working ?
I haven't had a chance to go back and work on it since then.





cheers, jerry
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFCxW+4IR7qMdg1EfYRAic1AJ9wtli0fZ3ZeX5b3hbbMD1i7y5GtACglMPx
AWWmCflVJAVl5k3F8q8M09w=
=PFUT
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list