[Samba] Winbind could not convert sid to gid...

Bastiaans, Remco r.bastiaans at rijnland.nl
Wed Sep 15 11:35:13 GMT 2004


Hi,

I'm using the Samba RPM's from Fedora Core 2 RPM's (3.0.7-2.FC2) as an
authentication backend for a Squid Proxy server.  It all seems to work fine,
until I (try to)authenticate against a domain-group..  I started trying with
3.0.6-2.FC2, which also didn't work...  This is a pretty clean/fresh
installation of Fedora Core 2, for whatever that's worth...

I've succeeded joining the Windows NT4 domain (RZH_NT)...  Winbind seems to
work fine at first.. I can test the trust-secret ok, even authenticate a
user from the domain (RBasti), it can see the domain-groups (Internet), get
te sid, but it can't convert the sid to a gid...

# wbinfo -t
checking the trust secret via RPC calls succeeded

# wbinfo -u |grep RBasti
RBasti

# wbinfo -a RBasti%********     (passwd blanked)
plaintext password authentication succeeded
challenge/response password authentication succeeded

# wbinfo -g |grep Internet
Internet

# wbinfo -n Internet
S-1-5-21-637226847-105070846-619646970-7160 Domain Group (2)

# wbinfo -Y S-1-5-21-637226847-105070846-619646970-7160
Could not convert sid S-1-5-21-637226847-105070846-619646970-7160 to gid

Any idea's?  I also don't see any domain-users/groups appearing in
/etc/passwd or /etc/group... I guess that's why wbinfo -Y is failing, but I
can't figure out how to find out what's preventing this from working...

Remco


More information about the samba mailing list