[PATCH] Rework idmap_ad

Jeremy Allison jra at samba.org
Thu Apr 7 22:26:44 UTC 2016


On Thu, Mar 31, 2016 at 12:18:55PM +0200, Volker Lendecke wrote:
> Hi!
> 
> The attached patchset is supposed to fix a longstanding bug in
> winbind's idmap_ad backend. Assume a configuration where you have sfu
> attributes in a trusted domain. Start winbind and immediately do a
> idmapping call (sid2xid or vice versa). This will fail if winbind did
> not have the chance yet to list the trusted domains from the DC it is
> joined to, the AD_STRUCT based code even in child processes depends on
> the winbindd_domain list to be correctly filled.
> 
> This patchset solves the issue just for the sfu idmap backend,
> hopefully the rest of the winbind code can follow later.
> 
> Comments appreciated!

Still reviewing this - just FYI for the list.



More information about the samba-technical mailing list