[Samba] posix gid mapping of built-in groups

Henrik Langos hlangos-samba at innominate.com
Fri Jun 27 03:51:34 MDT 2014

Hi Sven,

On 06/23/14 14:40, Sven Schwedas wrote:
> On 2014-06-23 13:32, Henrik Langos wrote:
>> Hi Louis,
>> Thank you for the link. I've seen your scripts before and it was on my
>> todo list to check it out and maybe even update the wiki
>> with a reference to it: https://wiki.samba.org/index.php/SysVol_Replication
>> However, my problem arises from not having Windows AD groups mapped to
>> the same posix uidnumber on all AD DCs, not from having changes made on
>> different DCs.
>> Is there a down side to providing posix gid numbers to all AD built-in
>> groups?
>> Does anybody have experience with that approach?
> As far as I know, there is no downside, and it might even be necessary
> for winbind; we're running with Posix attributes on all our groups
> without issues so far.

I've added Unix attributes to all my groups using ADUC.
Now every time I enter the "UNIX Attributes" tab in the properties
of those groups, I get a small error dialog saying "Execution denied"
(actually it says "Ausführung verweigert" as it is a German Windows 7 ).

I click on OK (there is no other button) and I get to edit the Unix 
It doesn't seem to cause trouble apart from that little dialog.
Still I'd like to know what is happening there.

Any hint on what is to be executed and how to fix the issue?
Ideas how I may debug this ?


More information about the samba mailing list