[Samba] Samba Groups Vanished

Diarmuid Bourke dbourke at cp.dias.ie
Mon Aug 28 12:49:31 GMT 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hi,
Our Samba Groups appear to have vanished.

I've verified this by trying, "net group /domain" in windows and it
returns no results. Trying "net rpc group -S nuada" on our master server
returns nothing either.
"net rpc info" on both our master and backup return

Domain Name: DIAS
Domain SID: S-1-5-21-463069746-3761697030-3888642000
Sequence number: 1156762378
Num users: 63
Num domain groups: 0
Num local groups: 0

Groups used work until recently and they exist in our ldap database. We
have a primary domain controller with the master ldap database on it and
a backup domain controller with a slave ldap database on it. Our version
of samba is Version 3.0.23 and openldap is 2.3.24

and below are the relevant sections of smb.conf from our PDC

[global]
workgroup = DIAS
netbios name = NUADA
preferred master = Yes
domain master = Yes
local master = Yes
passdb backend = ldapsam:ldap://127.0.0.1

# User pass configuration
security = user
encrypt passwords = true

# LDAP Configuration

domain logons = Yes
wins support = Yes
ldap suffix = dc=cp,dc=dias,dc=ie
ldap machine suffix = ou=people
ldap user suffix = ou=people
ldap group suffix = ou=group
ldap idmap suffix = ou=Idmap
ldap admin dn = cn=samba,ou=specialusers,dc=cp,dc=dias,dc=ie
idmap backend = ldap:ldap://127.0.0.1
idmap uid = 10000-20000
idmap gid = 10000-20000
map acl inherit = Yes
- --------------------------------

Trying an ldapsearch to show groups exist in ldap returns..

ldapsearch -x -b cn=geotech,ou=group,dc=cp,dc=dias,dc=ie

dn: cn=geotech,ou=group,dc=cp,dc=dias,dc=ie
objectClass: posixGroup
objectClass: sambaGroupMapping
cn: geotech
gidNumber: 1932
sambaSID: S-1-5-21-463069746-3761697030-3888642000-4865
sambaGroupType: 2
displayName: geotech
memberUid: lcollins
memberUid: choran
memberUid: seismo
- -----------------------------

I've cut out configuration statements for
briefness but if you need them I can post them. Thanks in advance.

Diarmuid
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFE8uZb3VcUOgGPPMMRAokOAJ9DKKAH2+VLKG5kYuuH8KAqKuegdQCeLnPd
vozAd5x7JDuw/tcD9hF1ec8=
=Uvi/
-----END PGP SIGNATURE-----


More information about the samba mailing list