Thu Mar 18 17:34:04 MDT 2010

level account).   Domain Controllers should have the same SID as your
SCOIL sid, but this is clearly different.  So maybe the mapping from
userids in winbind is messed up?

> More info:
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
> net getlocalsid yeilds :-
> SID for domain SCOIL is: S-1-5-21-399018149-2014173726-3152914669
> In the LDAP DB I have :-
> sambaDomainName=3DBBNS,ou=3Ddomains,dc=3Dbbns,dc=3Die
> =A0 =A0 =A0 =A0sambaSID=3DS-1-5-21-399018149-2014173726-3152914669
> I am using Debian 5
> Any help to debug this is welcome
> //Ger
> --
You should read the thread in the last couple of weeks on messed up
uid/gid/rid mappings in this thread from May 21:
[Samba] Moving to another idmap backend

Does the client happen to be Win7?   Mark Russinovich of SysInternals,
now Microsoft does not see the need for SIDs and was pushing for them
to be removed, but i doubt that has happened yet.
SECURITY_NT_NON_UNIQUE	S-1-5-21	SIDS are not unique.

Mark Russinovich on sids

