[Samba] Wierd winbind results

Gerald (Jerry) Carter jerry at samba.org
Mon Dec 8 19:08:19 GMT 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

David Chait wrote:
| Hi all,
|     I have a Samba 3 machine joined to a AD Child Domain, which
| is a member of a large forrest. The machine joined the AD
| domain fine and it can query/log in to it. However for some
|reason Winbind is showing incomplete information. wbinfo -g
| shows groups from every domain in the forrest as it should,
| though wbinfo -u does not, it shows some of the child domains
| but does not show accounts from the domain that this computer
| is a direct member of, nor the top level. Has anyone else seen
| this sort of behaviour before?

Are these native mode domains ?  If so it could be related to the ACLs
on entries in AD.  Use ADSIedit.exe to check the permissions.  Newly
create objects might not allow enumeration by a non-admin (or anonymous
user).




cheers, jerry

~ ----------------------------------------------------------------------
~ Hewlett-Packard            ------------------------- http://www.hp.com
~ SAMBA Team                 ---------------------- http://www.samba.org
~ GnuPG Key                  ---- http://www.plainjoe.org/gpg_public.asc
~ "If we're adding to the noise, turn off this song" --Switchfoot (2003)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE/1MwiIR7qMdg1EfYRAgJcAKCy/3D0d0RKMyE2T3kCUY63pbYRHwCfaN7s
g6E6Zr7myc/XBMkcSbvitXU=
=BO58
-----END PGP SIGNATURE-----



More information about the samba mailing list