[Samba] unix_primary_group and unix_nss_info for rfc2307 idmap backend

Rowland penny rpenny at samba.org
Thu Dec 19 13:27:31 UTC 2019

On 19/12/2019 11:20, Sebastian Lisic via samba wrote:
> Hi,
> In winbind, are there any plans to add the idmap_ad options "unix_primary_group" and "unix_nss_info" to the idmap_rfc2307 backend?
> I am using an ldap proxy to preserve the UNIX uids and gids between two domains, and it would be nice to also share the shell setting and the UNIX primary group as well.

This backend seems to be designed as a bridge between AD and an ldap 
server and only implements the 'idmap' API. It might be possible to 
modify it to obtain the attributes you refer to, but I do not think this 
is likely to be on anyone's TODO list.

If your domains do have the required rfc2307 attributes and trusts in 
place, you could use the idmap_ad backend instead, provided they are all 
AD domains.


More information about the samba mailing list