[Samba] Nested groups when using RFC2307

Sérgio Basto sergio at serjux.com
Tue May 26 00:21:21 UTC 2020


On Mon, 2020-05-25 at 17:09 -0300, Marcio Merlone via samba wrote:
> Hi,
> 
> Just noticed, I am unable to use nested groups when relying on
> RFC2307 
> for filesystem permissions, am I wright? What have I missed?
> 
> (Samba 4.12 on Buster, 2008R2 domain level)
> 
> Any migration path to stop using RFC2307 and go to pure idmap
> without 
> loosing all permissions on a 6T filesystem? Is that a solution?

have you checked "winbind expand groups" options ? 

# Check depth of nested groups, ! slows down you samba, if to much
groups depth
# Samba default is 0, i suggest a minimal of 2 in this setup, advices
is 4.
winbind expand groups = 4


> Regards,
> 
> -- 
> *Marcio Merlone*
-- 
Sérgio M. B.




More information about the samba mailing list