[Samba] Avoiding uid conflicts between rfc2307 user/groups and computers

Rowland Penny rpenny at samba.org
Fri Jan 12 16:56:53 UTC 2018


On Fri, 12 Jan 2018 17:42:44 +0100
Björn JACKE via samba <samba at lists.samba.org> wrote:

> On 2018-01-12 at 16:24 +0000 Rowland Penny via samba sent off:
> > > Clearly, also 'Domain Computers' group have to get assigned an
> > > GID, right?
> > 
> > Yes.
> > 
> > The question is, do you need to do this ? Will a computer own
> > anything on a Unix machine ?
> 
> it's not the question if he owns anything. It's enough that the
> machine uses the machine account during the tree connect
> to make it fail without a corresponding posix account.
> 
> Björn

Surely the authentication of choice would be kerberos and this wouldn't
require a posix account.

Rowland



More information about the samba mailing list