[Samba] Winbind missing secondary groups
rpenny at samba.org
Wed Jul 27 20:24:25 UTC 2022
On Wed, 2022-07-27 at 16:05 -0400, Luc Lalonde via samba wrote:
> I corrected all the errors you mentionned in my config... Still a no
> for secondary groups.
> Other answers below:
> On 2022-07-27 15:19, Rowland Penny via samba wrote:
> > Does 'Domain Users' have a gidNumber ?
> No, but I tried setting one... changes nothing (after restarting
> winbind, net cache flush)
> > Do all your users have a uidNumber & gidNumber ?
> > Do all your groups have a gidNumber ?
> > Are all these numbers inside the 1000-999999 range ?
Strange, what version of Samba is this ?
I am using 4.15.7 with these lines in smb.conf:
winbind expand groups = 2
idmap config * : backend = tdb
idmap config * : range = 3000-7999
idmap config SAMDOM : backend = ad
idmap config SAMDOM : schema_mode = rfc2307
idmap config SAMDOM : unix_nss_info = yes
idmap config SAMDOM : range = 10000-999999
and I get this:
rowland at devstation:~$ id
uid=10000(rowland) gid=10000(domain users) groups=10000(domain
The only real difference is that I do not use 'unix_primary_group =
As you can see, I get a lot of groups. I would double check everything.
More information about the samba