Samba AD DC and winbindd

Rowland Penny repenny241155 at
Mon Feb 15 16:30:01 UTC 2016

On 15/02/16 14:29, Andreas Schneider wrote:
> On Monday 15 February 2016 12:38:26 Rowland Penny wrote:
>> On 15/02/16 12:19, Stefan Metzmacher wrote:
>>> Hi Rowland,
>>>> winbind use default domain = yes
>>> I think should not be supported on a AD DC, it's ugly enough
>>> that it exists at all...
>> Well the line works on a domain member and it works on 4.2.x, so either
>> it should still work on a 4.3.x DC or it should be removed completely
>> for consistency, if nothing else.
>>> I would guess 4.0 and 4.1 also always report:
>>> TEST\user1:*:10000:10000::/home/user1:/bin/sh
>> You are probably right, it never worked for me and I only found it
>> whilst testing something else.
> To be honest, I would vote for removing the 'winbind use default domain'
> option completely. I have a lot of downstream bugs with issues only because of
> this options.
> It creates more trouble than it solves a problem ...
> Cheers,
> 	-- andreas

I personally am not bother either way, if the option wasn't there, I 
would quickly get used to it not being there.
It is available on a domain member and it was available on a DC, even if 
it wasn't meant to be, so it either needs to be removed everywhere or 
fixed on the DC.


More information about the samba-technical mailing list