[Samba] upgraded DC shows IDs instead of usernames
Christopher Cox
chriscox at endlessnow.com
Mon May 11 15:13:40 UTC 2020
On 5/11/20 10:11 AM, Rowland penny via samba wrote:
> On 11/05/2020 15:56, Christopher Cox via samba wrote:
>> Of course, this really isn't "the problem". Nothing wrong with apparmor or
>> selinux. The problem is assuming a "one set of rules fits all" mentality.
>>
>> I actually like apparmor. But maybe if people knew how to use it to make
>> their own policies instead of accepting (note: In this case the "accept" is
>> through the distribution's install) the assumptions of another...
>>
>> Granted, I don't want to go total "Lennart" (you don't have to use systemd,
>> etc.), but felt it needed to be said anyhow.
>
> I never said there is anything wrong with Apparmor, it is (like Selinux)
> extremely hard to configure unless you are a rocket scientist. If they want more
> people to use it, they need to come up with some way to automatically configure
> it. If they don't, you are going to continue reading things like 'first turn off
> Apparmor' in howto's.
>
> Apparmor is great when it works, it is just getting it to work that is the hard
> part ;-)
It has a reasonable runtime inspection mechanism that makes things pretty easy
(IMHO).
More information about the samba
mailing list