[Samba] Problems with groups, minimum gidnumber?

Rowland penny rpenny at samba.org
Fri May 15 18:46:58 UTC 2020


On 15/05/2020 19:29, Harald Hannelius wrote:
>
> On Fri, 15 May 2020, Rowland penny via samba wrote:
>> On 15/05/2020 18:26, Harald Hannelius wrote:
>>> On Fri, 15 May 2020, Rowland penny via samba wrote:
>>>> On 15/05/2020 16:33, Harald Hannelius wrote:
>>>>> If there's a way to copy the sambaNTPassword password-hash from 
>>>>> the LDAP for the Samba 3 DC with samba-tool I would have loved to 
>>>>> find that information long ago :)
>>>> Why do you need the sambaNTPassword ?
>>>
>>> So the users would have the same password. I don't have time to wait 
>>> for our IDM to change the passwords one by one.
>> That is another reason to lose the IDM, AD is an IDM.
>
> Do You mean Azure AD? :)
No, but connection to this is on the to do list.
>
> We have so many different systems, and sadly we have to perform some 
> staging of users to external pages before SAML-logins and so on that 
> our IDM has it's job to do.
AD can do what IPA can do and more
>
> And even though we're moving from Samba3+OpenLDAP the OpenLDAP stays, 
> because we have several systems integrated against that.
Probably most, if not all, could be integrated into AD
> I have to look into trust relationships, but I'm not that happy about 
> that. Not sure if I will go that way.
>
> Our users and computers are sitting in our Win AD, it will sure be 
> interesting this.
>
> Previously computers happily tried with the user's password when 
> connecting to a share. It looks like there's a small learning curve 
> ahead for our users.

Done correctly, your users will not notice.

Rowland






More information about the samba mailing list