[Samba] chown and AD users
Rowland penny
rpenny at samba.org
Mon Jun 3 14:58:23 UTC 2019
On 03/06/2019 15:17, Nico wrote:
> Sorry, I forgot to precise : It's on a Samba AD DC (v4.10.3 and CentOS
> 7).
>
> My smb.conf :
>
> [global]
> Â Â Â server role = active directory domain controller
> Â Â Â netbios name = server_name
> Â Â Â realm = DOMAIN.LAN
> Â Â Â workgroup = DOMAIN
>
> Â Â Â server services = -dns
>
> Â Â Â idmap_ldb:use rfc2307 = yes
>
> Â Â Â bind interfaces only = yes
> Â Â Â interfaces = p3p1
>
Nothing wrong with the lines above
> idmap config DOMAIN:range = 600-4000000
> Â Â Â idmap config DOMAIN:backend = tdb
> Â Â Â idmap uid = 600-4000000
> Â Â Â idmap gid = 600-4000000
>
> Â Â Â winbind gid = 600-4000000
> Â Â Â winbind uid = 600-4000000
Well, if you are going to get it wrong, you might as well get it
absolutely totally wrong ;-)
To put it another way, remove the lines above, they have no place in a
Samba AD DC smb.conf
> winbind enum groups = yes
> Â Â Â winbind enum users = yes
Remove the lines above once you are sure everything is working correctly
> winbind use default domain = yes
The line above doesn't work on a DC
> winbind nested groups = yes
> Â Â Â winbind refresh tickets = yes
>
> Â Â Â vfs objects = acl_xattr
> Â Â Â map acl inherit = yes
> Â Â Â store dos attributes = yes
>
The three lines above definitely shouldn't be in a Samba DC smb.conf
> log level = 3
> Â Â Â log file = /var/log/samba/samba_ad.log
> Â Â Â max log size = 50
>
> [sysvol]
> Â Â Â path = /usr/local/samba/var/locks/sysvol
> Â Â Â read only = No
>
> [netlogon]
> Â Â Â path = /usr/local/samba/var/locks/sysvol/ensim.univ-lemans.fr/scripts
> Â Â Â read only = No
>
> My nsswitch.conf :
> Signature mail
> passwd:Â Â Â Â compat winbind
> shadow:Â Â Â Â compat winbind
> group:Â Â Â Â Â compat winbind
Remove 'winbind' from the 'shadow' line, it can cause problems and
doesn't actually do anything.
>
> hosts:Â Â Â Â Â files dns wins
>
AD runs on DNS, it doesn't use wins.
Do the libnss_winbind links exist ?
does 'getent passwd username' produce output ?
Rowland
More information about the samba
mailing list