[Samba] Lots of "Failed to create" error messages after upgrading to 2.0.25c

Gerald (Jerry) Carter jerry at samba.org
Tue Aug 28 14:17:41 GMT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Eric Evans wrote:
> Hello Jerry et al,
> 
> So why is the idmap configuration option needed in our configuration?  
> It was not needed in 3.0.22, so why does it suddenly become
> necessary in 3.0.25c?

Simply put, the default value for 'winbind nested groups' change
in 3.0.23.  Therefore, in order to support the NT4 local group
model in winbindd, you have to have an idmap backend.

Just like a Windows client add 'Domain Admins' to the local
Administrators group, smbd attempts to do the same.  You still
get a local Administrators group without winbindd's nested
groups.  You just cannot manipulate the membership.

Running a production server at level 2 is a little odd IMO.
Generally log level = 1 is considered best practice.  If you
want level 2 (and run winbindd without an idmap backend),
then you will have to live with the messages for now.




cheers, jerry
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFG1C6FIR7qMdg1EfYRAi7YAKCxLTvsb26j7aX7iZ0DqINkp4v3OQCfV1Vr
75NQ9fXSWVutoM2/MIT7pLw=
=uo57
-----END PGP SIGNATURE-----


More information about the samba mailing list