[PATCH] Rework idmap_ad
Jeremy Allison
jra at samba.org
Thu Apr 7 22:26:44 UTC 2016
On Thu, Mar 31, 2016 at 12:18:55PM +0200, Volker Lendecke wrote:
> Hi!
>
> The attached patchset is supposed to fix a longstanding bug in
> winbind's idmap_ad backend. Assume a configuration where you have sfu
> attributes in a trusted domain. Start winbind and immediately do a
> idmapping call (sid2xid or vice versa). This will fail if winbind did
> not have the chance yet to list the trusted domains from the DC it is
> joined to, the AD_STRUCT based code even in child processes depends on
> the winbindd_domain list to be correctly filled.
>
> This patchset solves the issue just for the sfu idmap backend,
> hopefully the rest of the winbind code can follow later.
>
> Comments appreciated!
Still reviewing this - just FYI for the list.
More information about the samba-technical
mailing list