[Samba] UNIX accounts needed for machine accounts?

Ralf Hornik Mailings ralf at best.homeunix.org
Wed Dec 16 05:20:48 MST 2009


Lukas Haase <lukashaase at gmx.at> schrieb:

> It would be great if libnss-ldap would support users from different  
> trees (than I could take ou=int,ou=users AND ou=machines) but I  
> guess this is not possible...

I don't see a problem here. You can just set up your ldap to

ou=users,ou=ext,dc=domain,dc=com
ou=groups,ou=ext,dc=domain,dc=com

and

ou=machines,ou=int,dc=domain,dc=com
ou=users,ou=int,dc=domain,dc=com
ou=groups,ou=int,dc=domain,dc=com

then point libnss on your samba related machines to  
"ou=int,dc=domain,dc=com" and any other machines to dc=domain,dc=com.




More information about the samba mailing list