[Samba] demote ad dc

Rowland Penny rpenny at samba.org
Sat Aug 21 10:24:44 UTC 2021

On Sat, 2021-08-21 at 11:07 +0200, Andrea Ballarati via samba wrote:
> Thank you Rowland.
> There are no uid# or gid# in DC's smb.conf.
> My users are all win machine using domain for authentication and the 
> fileserver.
> No access is needed locally on the linux servers (we have 2 file
> servers 
> in syncro for security reasons) or on the home directories.
> In this scenario what configuration do you suggest?

Use either the 'rid' or 'autorid' winbind backend. If you only have one
domain (no trusts, or likely to have), use the 'rid' backend, but if
you have trusts, then use 'autorid'.


More information about the samba mailing list