RFC [Patch] winbind expand groups doc

Andrew Bartlett abartlet at samba.org
Thu Sep 28 22:12:56 UTC 2017

On Thu, 2017-09-28 at 16:02 +0200, Stefan Metzmacher via samba-
technical wrote:
> Hi Louis,

> The effective group memberships are still in place. The unix token
> will
> have them. "id" should be able to show them, after an successful
> authentication.
> This options is really only for broken applications which use
> something
> like: getent group <group> in order to verify that a users if a
> member
> of the group.

It should be noted for context that this is quite rare, because it is
very slow on larger groups most applications were fixed to use the unix
token or nss's getgrouplist() instead.

Andrew Bartlett

> Is there an RDP service for linux that qualifies itself as such a
> broken
> app?
> metze
Andrew Bartlett
Authentication Developer, Samba Team         https://samba.org
Samba Development and Support, Catalyst IT   

More information about the samba-technical mailing list