[Samba] Fw: idmap woes after upgrade

Tim ODriscoll tim.odriscoll at lambrookschool.co.uk
Sat May 27 12:53:16 UTC 2017

On 27 May 2017 13:38
> There are a couple of attributes in AD that you can use to do this.
I've got uidNumber and gidNumber set properly, so I think I've got that covered...

> OK, you only need to keep idmap.ldb in sync if you use both DCs as
> fileservers or if you are using GPOs.
Great - I can do that.

> The xidNumber attributes in idmap.ldb are created automatically, but if
> the user is given a uidNumber attribute, this will always be used
> instead.
Right, so my uidNumber and gidNumber attributes are working fine it seems, but they're not mapping at the filesystem level.

I've got winbind in my nsswitch.conf. I don't want to grant user access to the servers via ssh or anything, so I don't need pam_winbind, right?

What does the mapping of uidNumber to username on the filesystem so I can use chown etc?

Many thanks again,


More information about the samba mailing list