winbind 3+4: different behavoiur with "winbind use default domain = yes"

Thomas Mueller thomas at
Thu Sep 6 07:26:12 MDT 2012


still experimenting with samba4. :)

on the server with winbind4 (on the server dc1, wheezy with samba4 git) 
and "winbind use default domain = yes" in smb.conf I see not the same 
behaviour as with winbind3 (on the workstation wks, centos 6).

wks#> id user
uid=10021(user) gid=10049(g_user) groups=10049(g_user)

dc1#> id user
uid=10021(DOMAIN\user) gid=513(Domain Users) groups=513(Domain Users)

so the server looks up "user" and gets DOMAIN\user back. Seems that 
"winbind use default domain = yes" is partly working. 

Antother difference is that not both are using the windows primary group 
as the unix default group. s4 smb.conf contains "idmap_ldb:use rfc2307 = 
yes" and s3 smb.conf "winbind nss info = rfc2307". So one is using 
gidNumber and the other primaryGroupID.

Is winbind4 ready to use and still the recommended nss tool?

- Thomas

More information about the samba-technical mailing list