[Samba] winbind / trust questions and issues

Eric A. Hall ehall at ntrg.com
Mon Dec 20 09:17:10 MST 2010

On 12/15/2010 4:19 PM, Eric A. Hall wrote:

> First issue is that I would like to filter out the local (LABS) users and
> groups in winbind if possible.

I tried using "winbind: ignore domains = LABS" but this causes winbindd to
completely ignore its own domain, which in turn causes it to freak out,
dump core, and die

I have also tried using require_membership_of=SID for CORP/Domain Users
(the remote users I want to allow local access through winbind), but
pam_winbind complains about the foreign SID and then allows everybody to
login despite the error

Anything else I could try?

Eric A. Hall                                  http://www.eric-a-hall.com/
Network Technology Research Group                    http://www.ntrg.com/
Internet Core Protocols          http://www.oreilly.com/catalog/coreprot/

More information about the samba mailing list