[Samba] Change (fix) idmap config
Kees van Vloten
keesvanvloten at gmail.com
Wed Nov 2 18:05:13 UTC 2022
On 02-11-2022 18:58, Rowland Penny via samba wrote:
> On 02/11/2022 17:20, Michael Tokarev wrote:
>> 02.11.2022 20:14, Rowland Penny via samba wrote:
>>>> Some further comments report a new "join" is required before
>>>> restarting services.
>>>> Can this be a correct approach?
>>> If all else fails, it is worth trying, but 'leave' the domain first.
>> Rowland, why 'leave' it?
>> This way, the machine records will be deleted, including any
>> say, uidNumber. Why can't it re-join "to" an existing machine object?
>> I experimented with that yesterday and it worked fine without a 'leave'.
> net ads leave --keep-account
Samba seems to like to remove computer-accounts.
I noticed that a computer-account gets removed when the domain join
fails. It sounds logical when the join create the account. But
pre-provisioned computer-accounts are also removed on a failing join...
Is there a similar switch to prevent that behaviour?
More information about the samba