[Samba] problems with authentication

Rowland penny rpenny at samba.org
Tue Aug 6 06:49:57 UTC 2019

On 06/08/2019 04:05, Marcio Demetrio Bacci wrote:
> Hi,
> I have updated Samba 4.5.16 to version 4.10.6 and it is now working.
> >Remove 'winbind' from the 'shadow' line in /etc/nsswitch.conf
> OK.
> >Have you given your users a uidNumber attribute containing a unique
> number inside the range '100000-999999' ?
> Is this done through the Unix attributes in RSAT and for each user?

I will take that as 'No' then ;-)

Yes, you can do this via the users Unix attributes tab and yes, you need 
to do it for every Windows user that you want to be visible to Unix.

> >Have you also given 'Domain Users' a gidNumber attribute containing a
> number inside the same range ?
> Is this done for each custom group and for the "Domain Users" default 
> group too?
Definitely for 'Domain Users', this group must have a gidNumber, or all 
your users will be invisible to Unix. As for any other group, most other 
Windows groups do not need to be visible to Unix, so do not need a 
gidNumber. Any groups you create may need to be visible to Unix and if 
they do, they will need a gidNumber.
> Will these changes affect user permissions on the Windows Server 2008 
> file server too ?
No, uidNumber & gidNumber attributes have no effect on Windows machines.


More information about the samba mailing list