New group mapping and the auth subsystem

Jeremy Allison jra at samba.org
Sun Dec 2 00:46:04 GMT 2001


On Sun, Dec 02, 2001 at 11:34:58AM +1100, Andrew Bartlett wrote:

> Ok, I'm not worried about the actual token - and I understand now that
> this is indeed machine-specific, but I am worried about the NT groups
> that make up that token, and I want to ensure that we don't waste the
> information we get when doing this.

So long as we save the groups list on doing a netlogon, or get
the groups list from the PAC, we're ok here (not losing info).

> The only stuff I've found at all refers to the lsalogonuser call, which
> in fact retuns a token.  (This is on each machine of course).  What I'm
> looking at is where the lsa gets the info for that token.



More information about the samba-technical mailing list