ldapsam:editposix

simo idra at samba.org
Thu Mar 2 13:44:00 GMT 2006


On Thu, 2006-03-02 at 09:04 +0100, Tomasz Chmielewski wrote:
> simo wrote:
> > On Wed, 2006-03-01 at 23:01 +0100, Tomasz Chmielewski wrote:
> >> Volker Lendecke wrote:
> >>> Hi, Simo!
> >>>
> >>> As already said on irc: I've tested editing posix accounts
> >>> in ldapsam without any 'add user script' & friends. This
> >>> looks very good, thanks!
> >>>
> >>> For all who haven't seen this yet, let me advertise Simo's
> >>> work a bit: If you set 'ldapsam:trusted=yes' and
> >>> 'ldapsam:editposix=yes' and you run winbind (even on a DC)
> >>> you can use usrmgr.exe to edit the posix users and groups
> >>> without any idealx scripts etc.
> >>>
> >>> Extremely cool feature I think, thanks Simo! :-)
> >> What about adding machine accounts when joining the domain? You'd still 
> >> need some "add user" script I guess?
> > 
> > Of course not.
> > The aim of editposix is to let samba directly create posixAccounts and
> > posixGroups in the ldap tree, and that's true also for workstation
> > accounts.
> 
> Wow, I'm impressed.
> 
> But it it possible to configure it to use a master LDAP for writes, and 
> slave for reads?

ldapsam already can do that (provided the slave give back proper
referrals). There is no difference in that regard.

Simo.

-- 
Simo Sorce
Samba Team GPL Compliance Officer
email: idra at samba.org
http://samba.org



More information about the samba-technical mailing list