[Samba] Best practice - local groups - domain groups

Karl Heinz Wichmann wichmann-karl at web.de
Wed Jul 23 09:15:15 MDT 2014


Hi Marc


Am 22.07.2014 19:21, schrieb Marc Muehlfeld:
> Am 22.07.2014 18:25, schrieb Karl Heinz Wichmann:
>> I have a generic questions about local / domain groups.
>>
>> We have 1 Domain and 20 sites. In each site is a domain controller and a
>> member server. The user have only access to share on the memberserver on
>> their site.
>>
>> user -> domain group -> share
>> or
>> user -> domain group -> local group -> share
>
>
> I see no advantage to have a domain group nested in a local group, that
> is allowed to enter a share.
>
>
>
>> Should a share be accessible for a local group or a domain group?
>> (replicaton, traffic, failure safety, security)
>
> Replication traffic is low. Only changes are transfered. I don't see any
> failure safety and security advantages. Examples?
>
>

We have multiple OU. For each site (ou) we have an sub admin to manage 
the accounts, groups and shares. We don't want that an user in ou1 can 
access to a share in ou2.


>
> Regards,
> Marc
>
>

Regards,
Karl Heinz


More information about the samba mailing list