[Samba] Making Linux and domain users the same

Andrew Bartlett abartlet at samba.org
Thu Mar 14 21:42:26 MDT 2013

On Fri, 2013-03-08 at 13:48 -0500, Michael DePaulo wrote:
> Can somebody confirm that idmap_nss works on Samba4 in AD DC mode?

It does not.  However, you should just use nss_winbind on the DC, and so
make your AD users local users that way. 

> If nobody can, I can test it on my Samba 4.0.3 machine. Currently I'm
> editing idmap.ldb to map domain users to local unix users.

Did you have a Samba domain before that?  We should have done a similar
mapping as part of the classicupgrade. 

The standard way of doing this is currently to set: idmap_ldb:use
rfc2307=yes in the smb.conf, and use the uidNumber and gidNumber
attributes in the directory.

Andrew Bartlett
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org

More information about the samba mailing list