[Samba] Samba AD DC: Keeping LDAP content in VCS

Rowland Penny rpenny at samba.org
Sun Jul 25 12:59:29 UTC 2021

On Sun, 2021-07-25 at 14:25 +0200, Lorenz Schori wrote:
> Hi,
> On Sun, 25 Jul 2021 13:09:32 +0100
> Rowland Penny via samba <samba at lists.samba.org> wrote:
> > On Sun, 2021-07-25 at 13:10 +0200, Lorenz Schori via samba wrote:
> > [...]
> > If Samba is involved, then I probably should mention that apart
> > from a
> > Samba AD DC (where once something is added to the schema, it cannot
> > be
> > removed), Samba only really uses ldap for NT4-style domains and
> > they
> > [...]
> I'd like to manage the structure (i.e., organization units and
> groups)
> of a Samba AD DC that way.

You can do what you like with OU's and you can create groups, but you
cannot change the schema and it is inadvisable to delete the standard
groups e.g. Domain Users

>  If there is a better interface for directory
> management than ldif, 

AD uses ldifs to add users, groups etc , so I do not know of any other
interface to use

> then I sure like to have some pointers on that as
> well. Also note, this is not really about the LDAP schema.

No, it sounds like it really about changing where the users, groups and
computers are stored in AD and I cannot see where the versioning comes


More information about the samba mailing list