On Wed, 10 Feb 2021, L.P.H. van Belle via samba wrote:

> Follow these guidlines (for all servers basicly)
> Make sure the primary dns is used first, so the one you
> provisoned samba with.

The problem was that DC1 had it's host names in the wrong order in 
/etc/hosts. DC2 didn't have any names there, so it relied on DNS which 
returned the correct FQDN.

Once I fixed /etc/hosts on DC1 as below, the resolving of usernames now 
takes 10 seconds. I can live with that, even though Samba + OpenLDAP was 
much faster in this aspect.

That check-script should be a standard part of every DC-install :)

> /etc/hosts  (DC1)
>	sad1.sad.arcada.fi sad1.arcada.fi	sad1
> 2001:708:170:33::91 sad1.sad.arcada.fi sad1.arcada.fi	 sad1


> this is a problem.
>> idmap config SAD:range = 500-4000000
> Debian system start with unix id from 1000 unless you adjusted the defaults
> it adviced to use/start, outside the system range
> (cat /etc/adduser.conf)

Our uids pre-date Debian. They are a mix of Solaris and Slackware usernames 
so we start at 500. This will fix itself over time, there aren't many users 
left within the 500-999 range.

Thank You.


Harald Hannelius | harald.hannelius/a\arcada.fi | +358 50 594 1020

