[Samba] Samba PDC/LDAP how to get Win2000 Administrator account?

> I have set up samba/PDC /LDAP and am able to logon as a normal user,
> however I am not sure how to create an LDAP user that has
> Administrator privileges on a Windows 2000 PC.

You need to have a unix group, to which you map a windows group. Which
tool you use depends on which release of samba3 you are using. Up to
alpha23 used smbgroupedit. And IIRC it only works with LDAP in alpha23
or later. See the man page for details, but basically:

1) find the SID of the windows group:
# smbgroupedit -s
2)Create a unix group for that
# groupadd domadm
3)map the SID to the unix group:
# smbgroupedit -c <SID> -u <unix group>
4)Add unix users to the unix group, and they should be domain admins

> The Samba/LDAP howtos and guides don't seem to cover this topic much.
> If anyone could let me know what I need to do to have administrative
> privileges on a Win2000 machine I'd greatly appreciate it.

This is the stuff I have not got to yet in
http://ranger.dnsalias.com/samba-ldap-advanced.html . Contributions
welcome, otherwise I will try and finish that bit of it tomorrow.


