[Samba] ldap machine attributes not filled correctly when join a domain

emmanuel musso emmanuel.musso at iut-tlse3.fr
Tue Jan 30 08:22:27 GMT 2007


When a windows xp workstation join a domain, by windows gui parameters, ldap
machine attributes are not filled correctly:

- No attribute sambaprimarygroupsid (before, there was one terminated by 515)
- rid (of sambasid) is not equal a 2*uid+1000

If i create a user, rid (sambasid) equal a 2*uid + 1000 (and sambaprimarygrousid
terminated by 513)

All the others samba attributes are ok
Same problem if i use "smbldap-useradd -w" before joining the domain; Posix
attributes are created by "smbldap-useradd -w", and samba attributes are
created the first time workstation join the domain, allways with bad sambasid
and without sambaprimarygroupsid.

Same problem if i use "net join" on a linux smbclient with winbind

In all cases, my workstation is connected to the domain, and user can use it.

I didn't change my config, and i don't know since how many time i've the
problem; (perhaps since an update ?). I know my computers who joined the domain
in August month are ok, with  sambaprimarygroupsid present, and valid sambasid
(rid = 2* uid + 1000).
I have 2 Domain with the same problem

My config:
- Server
samba 3.0.23d-4 on debian testing, with daily updates
smbldap-tools 0.9.2-3
- worstation:
windows xp sp2
windows 2000 sp4
kdm on debian with smbclient and winbind

Kinds regards
Emmanuel musso
technicien informatique
I.U.T. Paul Sabatier
Dépt Génie électrique 0562258241
Service informatique 0562258025

This message was sent using IMP, the Internet Messaging Program.

More information about the samba mailing list