[Samba] Make domain users and groups available on local server

Rowland Penny rpenny at samba.org
Wed Aug 10 17:14:12 UTC 2016

On Wed, 10 Aug 2016 12:54:36 -0400
lingpanda101--- via samba <samba at lists.samba.org> wrote:

> Hello,
>      Had an issue on one DC that wouldn't allow me to use 'id user'
> and get results. Looked to the Wiki to troubleshoot and couldn't find
> a link to a topic. I finally found the information I needed under
> 'Setup Samba as an AD Domain Member'.  I would think this should be
> listed under 'Advanced configuration' as well? Is it listed elsewhere
> and I simply over looked it? My issue was a invalid symbolic link.
> Thanks.

The problem is that Samba doesn't recommend using the DC for anything
other than authentication and storing GPOs.

There were lots of reasons why this was a good idea when Samba 4 was
first released, but a great deal of the reasons have been fixed.

Lots of users are now asking similar questions about using the DC as a
fileserver and I think it may be time to reconsider how the wiki is
laid out. Whilst still not recommending using the DC as a fileserver,
Samba needs to accept that people will (need to) use the DC as a
fileserver and the wiki needs to reflect this.


More information about the samba mailing list