[Samba] winbind: BUILTIN\users group gid 1001 conflict

Christoph Peus cp at peus.net
Sat Mar 24 10:13:05 GMT 2007

Hi everybody,

I've joined a fileserver running samba 3.0.24 to an AD domain using 
winbind and noticed that samba maps the "users" group SID (5-1-5-32-545) 
  to gid 1001 automatically. This seems to conflict with one of ~2000 
mappings I had to "inject" in winbinds winbindd_idmap.tdb by use of net 
idmap dump/restore, because the fileserver had millions of files with 
certain uid/gid ownership from a local passwd/group before I did the 
"net ads join". The gid 1001 was allocated to the group "nawi" in 
/etc/group before.
I'm unsure now which problems could be caused by this regarding security.
Is it possible - and usefull - to change this mapping to get a 
"BUILTIN\users" group as expected?


lunkwill / # net groupmap list -v
         SID       : S-1-5-32-544
         Unix gid  : 1000
         Unix group: BUILTIN\administrators
         Group type: Local Group
         Comment   :
         SID       : S-1-5-32-545
         Unix gid  : 1001
         Unix group: nawi
         Group type: Local Group
         Comment   :

More information about the samba mailing list