[Samba] Samba4 Using AD/UNIX attributes for home directory and shell not possible?

Gémes Géza geza at kzsdabas.hu
Sat Aug 10 22:31:29 MDT 2013


Hi,
> Hi,
>
> I'm would like to use the attributes in AD for home directory
> (homeDirectory) and the login shell  (loginShell) for users logging in via
> ssh to a linux box.
Samba 4.x has (from the point of view of domain membership) two modes:

1. Active directory domain controller
2. Standalone, domain member or classic (NT4-like) domain controller

In the first case only the samba binary should run, which takes care of 
the winbind task (mapping user attributes) too. Unfortunately it can't 
retrieve homedir and shell attributes from the directory.

In the second case a separate winbind instance is/should be running 
which is able to use those mapping from the directory, so if you are not 
running an AD DC on the box in question, please send your whole config 
to be able to help debugging it.
> I added the following parameters in the global-Section of
> /etc/samba/smb.conf:
>     winbind nss info = rfc2307
>     idmap_ldb:use rfc2307 = yes
>
> Also I set the attributes for a test-user (called tim) with some values.
>
> But when calling "getent passwd" I got the following result:
> ...
> SHADOW\tim:*:3000017:100:Tim Testinger:/home/SHADOW/tim:/bin/false
>
> So it seems that winbind is ignoring AD attributes. Is this a bug or did I
> misconfigure my samba installation?
>
> Best Regards
> Markus
>
Regards

Geza Gemes


More information about the samba mailing list