[Samba] Should Samba-tool RODC preload be run periodically?

Andrew Bartlett abartlet at samba.org
Thu Nov 30 17:34:55 UTC 2017


On Thu, 2017-11-30 at 15:46 +0000, Andrej Gessel via samba wrote:
> Hello Andrew,
> 
> thank you for the answer.
> 
> 1) User credentials need to be preloaded with samba-tool to be 
> automatically replicated later if they change, its correct?

No, preloading just makes the first login faster.

> 2) And if user try to login on RODC without preloaded credentials, this 
> credentials will not be cached? (as described in samba wiki)

No, the criteria for being cached is if the user account is in the
allowed rodc replication group and not in the denied one. 

Can you point me at the incorrect section of the wiki?

> We using Samba 4.7.3 for RODC.

Good.

Andrew Bartlett
-- 
Andrew Bartlett                       http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba




More information about the samba mailing list