[Samba] Managing Samba Active directory.

Sketch sketch at rednsx.org
Tue May 5 08:11:57 MDT 2015

Great summary from Luke, but I would add a couple of things:

> A combination of the samba-tool command and pdbedit can achieve most 
> things...Our internal documentation also says you need to use the ADUC 
> tools to add UNIX Attributes to a Security Group. There might be a way 
> to do it on the command line but none of us have seemed to have bothered 
> to figure it out :-)

I though pdbedit was only for non-active directory setups?  However, it's 
easy to add attributes to a user manually with ldbedit or via script with 
ldbmodify.  There are also samba-tool options to add most of the common 
ones at user creation time.  See "samba-tool user add --help".

> I would recommend a single Windows Server (2012) with the ADUC tools 
> installed for management (you could probably get by with Win8.1 but 
> Server is less "graphical").

I would recommend not wasting your money on Windows Server, as the ADUC 
tools are identical between server and desktop versions of windows.

More information about the samba mailing list