[Samba] security = user, multiple Sambas, shared LDAP

Daniel Pocock daniel at pocock.com.au
Tue Feb 26 20:59:00 GMT 2008

Consider the following scenario:

- a single OpenLDAP server, with a single instance of the object class 
sambaDomain and a single SID:

dn: sambaDomainName=myserver,ou=samba,dc=example,dc=com
objectClass: sambaDomain
sambaDomainName: MYGROUP
sambaSID: S-1-2-3

- multiple Samba servers, each with the following configuration:

   security = user
   workgroup = MYGROUP

Is this a valid configuration?  Or does the SMB protocol require the 
domain security to be used (security = domain) when all servers share a 
single LDAP backend?



