[Samba] workaround needed for Security Principals, and SID's mapping bug.

Rowland Penny rpenny at samba.org
Fri Dec 2 16:27:36 UTC 2016


On Fri, 2 Dec 2016 17:10:06 +0100
"L.P.H. van Belle via samba" <samba at lists.samba.org> wrote:

> No, i believe that guy is wrong.
> 
> MS-DTYP 
> https://msdn.microsoft.com/en-us/library/cc980032.aspx 
> 
> NT AUTHORITY\SYSTEM S-1-5-18
> NT AUTHORITY\authenticated users S-1-5-11 
> Etc etc. 
> 
> Monday i'll have a look again. 
> 
> Have a nice weeken everybody. 
> 
> Greetz, 
> 
> Louis
> 
> 

 There may be something in what the guy is saying, he is saying that
 'SYSTEM' was being treated as a group and if you check in idmap.ldb
 'S-1-5-18' is 'ID_TYPE_BOTH'. I wonder if changing this to
 'ID_TYPE_UID' would have any affect ?

Rowland



More information about the samba mailing list