"net groupfilter" ?

Volker Lendecke Volker.Lendecke at SerNet.DE
Tue Dec 16 15:39:48 GMT 2008


On Tue, Dec 16, 2008 at 09:27:35AM -0600, Gerald (Jerry) Carter wrote:
> This is exactly how idmap_ad[ex] works now though.  I don't see how
> what you are proposing is a larger change.  Seems like the filtering
> just needs to be placed in the idmap plugin and you are done.

I wasn't sure this works fully correctly also for calls like
wbinfo -g, getent group <groupname> for nested groups and so
on. Sorry if I'm wrong there.

> > The patch as posted here is the quick and dirty fix for smbd
> > only.
> 
> I'm confused.  Not running Winbind implies that the Windows
> users and groups match a local unix user and therefore you
> shouldn't really have the > NGROUPS issue.  And if you run Winbind,
> Just add the filter to the idmap backend and case closed.
> So the smbd-only patch is really the wrong place to solve it IMO.
> Am I explaining myself ok?

Yes, thanks. I'll keep this locally until I've come up with
a proper, acceptable patch.

Thanks for the review,

Volker
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.samba.org/archive/samba-technical/attachments/20081216/31ec641a/attachment.bin


More information about the samba-technical mailing list