[Samba] problems accessing shares with force group

Rowland penny rpenny at samba.org
Wed Feb 3 10:02:30 UTC 2021

On 03/02/2021 07:46, Piviul via samba wrote:
> Il 02/02/21 17:15, Rowland penny via samba ha scritto:
>> [...]
>> There doesn't seem to be anything wrong with that smb.conf except for 
>> the 'wins server' line, you don't use wins with Samba AD.
> you are right, I forgot to remove it.
>>> Furthermore I don't know if it's normal but getent group or wbinfo 
>>> --group-info doesn't show member users but if I set winbind expand 
>>> groups to 1 the getent group and wbinfo --group-info shows correctly 
>>> the member users.
>> You need to fix that, 'getent passwd username' & 'getent group 
>> groupname' must produce output.
> ...I think I've not explained myself... yes both produce output but 
> getent group <groupname> doesn't produce the members of the group if I 
> don't set winbind expand groups to 1. For example this is what I see 
> if I don't set winbind expand groups to 1:
> $ getent group dominiocsa\\Domain\ Users
> DOMINIOCSA\domain users:x:10513:
> but all domain users are in Domain Users group. Do you think there is 
> something wrong in my samba configuration?

No, but I understand your 'problem' now. Try reading 'man smb.conf' 
about 'winbind expand groups'


More information about the samba mailing list