Secondary Groups with ldapsam WAS: Re: [Samba] net groupmap / domain admins problem

Hansjörg Maurer hansjoerg.maurer at
Fri Jan 9 14:39:34 GMT 2004


the reason for the problem was the group entry in /etc/nsswitch.conf
It was interpreted correctly by the systems tools like id, getent etc.

With an strace -f on the following testprogram
I have seen, that nsswitch.conf is opend, but libnss_ldap not...
Therefore it doesn't use ldap for the getgrouplist systemcall samba uses..

I adjusted my nsswitch.conf in order to work with the testtool, and 
samba does to...

Thank you for your help



#include <unistd.h>
#include <grp.h>
#include <sys/types.h>
#include <stdlib.h>

int main(void)
                   int ngroups = 16;
                     gid_t *groups
                                 = (gid_t *) malloc (ngroups * sizeof 
                             gid_t secondaries[1024];
                                     printf("%d\n", getgrouplist("root", 
0, groups, &ngroups));


Dr. Hansjörg Maurer
itsystems Deutschland AG
Linprunstr. 10
D-80335 München
Ph/Fax +49 89 52 04 68-41/-59

More information about the samba mailing list