[Samba] Re: ldapsearch and getent passd/group with nss winbind differs

Gerald (Jerry) Carter jerry at samba.org
Thu Aug 21 15:01:27 GMT 2008

Andreas Ladanyi wrote:

> Ok ! Could it be true this behavior is different between
> "security=domain" and "security=ads" ?
> Because we had to put the user to the group:
> - first on windows side in ActiveFirectory
> - second on unix site in AD in the tab "Members of"
> so winbind 3.0.24 client recognise the group membership 
> on unix side in "security=domain" mode.
> Now we changed to Samba 3.0.31 with security=ads 
> mode and the behavior is a bit different.

You lost me here.  Maybe due to the fact that I accustomed
to the Windows 2003 R2 Unix Attribute tab.  The only member
of tab I see is to control the Windows group memberships.

If I understand you correctly, you want to define a
different Unix group membership for the user rather than
honoring the Windows group membership.  Did I understand
you correct?

cheers, jerry
