[Samba] Mapping domain groups with winbind

Michael Gasch gasch at eva.mpg.de
Tue Jun 5 11:28:50 GMT 2007


i think a fine solution is to create a localgroup with

net sam createlocalgroup <group> and put your domain group into this group

this group will then get a SID-mapping and be also visible in windows
environments (e.g. security tabs if a windows client wants to edit the
ACL of this machine)


Jon Ferguson wrote:
> I've got several machines authenticating against AD via winbind.  What I
> would like to do is map Domain Users to various local groups, eg. audio,
> video, cdrom, etc.  Is this possible and if so, what is the
> correct/preferred way?

Michael Gasch
Max Planck Institute for Evolutionary Anthropology
Department of Human Evolution (IT Staff)
Deutscher Platz 6
D-04103 Leipzig

Phone: 49 (0)341 - 3550 137
       49 (0)341 - 3550 374

Fax:   49 (0)341 - 3550 399

More information about the samba mailing list