[Samba] upgraded DC shows IDs instead of usernames

Christopher Cox chriscox at endlessnow.com
Mon May 11 15:13:40 UTC 2020


On 5/11/20 10:11 AM, Rowland penny via samba wrote:
> On 11/05/2020 15:56, Christopher Cox via samba wrote:
>> Of course, this really isn't "the problem".  Nothing wrong with apparmor or 
>> selinux.  The problem is assuming a "one set of rules fits all" mentality.
>>
>> I actually like apparmor.  But maybe if people knew how to use it to make 
>> their own policies instead of accepting (note: In this case the "accept" is 
>> through the distribution's install) the assumptions of another...
>>
>> Granted, I don't want to go total "Lennart" (you don't have to use systemd, 
>> etc.), but felt it needed to be said anyhow.
> 
> I never said there is anything wrong with Apparmor, it is (like Selinux) 
> extremely hard to configure unless you are a rocket scientist. If they want more 
> people to use it, they need to come up with some way to automatically configure 
> it. If they don't, you are going to continue reading things like 'first turn off 
> Apparmor' in howto's.
> 
> Apparmor is great when it works, it is just getting it to work that is the hard 
> part ;-)

It has a reasonable runtime inspection mechanism that makes things pretty easy 
(IMHO).




More information about the samba mailing list