[Samba] Moving to AD for idmap backend

Vaughan, Robert J vaughar2 at gdls.com
Mon Nov 28 19:14:44 UTC 2022

> The problem is that you shouldn't overlap domain ranges, which you are 
> going to have to and this will lead to a collision somewhere down the 
> line when a user or group is created at the same time as another and 
> they both get the same ID number (yes it will happen, it is not case of 
> if, it is when).

Rowland, can you please expand on that? You must be talking about a Windows user or group (at the same time?) 

Is this because winbind must create a mapping for every user it sees in AD?  Even those users who are not Samba users and do not have uid specified?

Robert Vaughan

This is an e-mail from General Dynamics Land Systems. It is for the intended recipient only and may contain confidential and privileged information.  No one else may read, print, store, copy, forward or act in reliance on it or its attachments.  If you are not the intended recipient, please return this message to the sender and delete the message and any attachments from your computer. Your cooperation is appreciated.

More information about the samba mailing list