[Samba] idmap_ad and UID vs UIDnumber

Rowland Penny rowlandpenny at googlemail.com
Tue Feb 24 03:39:47 MST 2015

On 24/02/15 08:52, Greg Zartman wrote:
> I note from the man pages, that idmap_ad will only map users/groups IF you
> set the UIDnumber in the active directory.  In lookin in my active
> directory, there is a "Unix Attributes" tab with "UID" in that tab that you
> can set.  There is also and "Attributes Editor" tap where you can look at
> all attributes and edit the "UIDnumber"
> I just want to verify that you need to set the "UIDnumber" in the Attribute
> Tab???  I'm doing some trouble shooting and want to eliminate problems.
> Thanks!
> Greg

Hi Greg, the correct attribute is 'uidNumber', but microsoft being 
microsoft, they call it several different things and indeed 'UID' on the 
ADUC Unix Attributes tab does refer to 'uidNumber'.

Not sure about the 'UIDnumber' because I don't seem to have the tab you 
refer to, but it probably is referring to 'uidNumber', microsoft has 
just capitalized the first three letters.

Just watch out for the 'uid' attribute, this should contain the users 
logon name i.e. what is in 'sAMAccountName'


More information about the samba mailing list