question on ntlm_auth tool

Andrew Bartlett abartlet at
Fri Oct 20 10:09:24 GMT 2006

On Fri, 2006-10-20 at 01:32 -0700, Doug Moore wrote:
> On Thu Sep 9 22:50:44 GMT 2004, Andrew Bartlett wrote:
> > I am quite willing to add a new protocol that
> exports the group lists,
> > or potentially (in consultation with the squid team)
> add this additional
> > features to the existing squid-2.5-ntlmssp
> 'protocol'.
> > 
> > The information is all there, as you know, so it
> would not be a big
> > patch to pull out a string-converted list of SIDs.
> > 
> > (I would do this by passing them in the 'extra_data'
> of the winbindd
> > pipe protocol, separated from the username by a
> NULL, for example).
> Has such a change been made in the 2 years since?  I
> be happy to use it, instead of reinventing it.

We didn't really agree on the best way to do it.  I put an extra command
in Samba4 'UG' for user groups, but nothing in Samba3.

Most folks make do with the --require-membership-of parameter.

Andrew Bartlett

Andrew Bartlett                      
Authentication Developer, Samba Team 
Samba Developer, Red Hat Inc.        
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url :

More information about the samba-technical mailing list