[Samba] member domain idmap config ad/rid

Rowland Penny rpenny at samba.org
Wed May 31 14:59:46 UTC 2017

On Wed, 31 May 2017 11:12:51 -0300
Elias Pereira <empbilly at gmail.com> wrote:

> Rowland,
> I checked and got the entry for root in idmap.ldb
> To get 'getent' to show users on the DC, you need to have
> > libnss_winbind set up just like on a domain member.
> Okay. I installed the libnss-winbind package, configured the links to
> the lib, and now the getent passwd administrator works.
> Now, when running the testparm the error occurs:
> idmap range not specified for domain '*'
> ERROR: Invalid idmap range for domain *!
> I need an entry "idmap config *: range = 3000-7999" in smb.conf of AD?

No, you have hit a known bug. The 'idmap config ' work done for 4.6.0
seems to be causing this, you can safely ignore this error.


More information about the samba mailing list