mapping uids of file owners to SIDs for AD users

Ralph Böhme slow at samba.org
Wed Jan 25 17:49:58 UTC 2017


Hi Sumit!

On Wed, Jan 25, 2017 at 05:16:46PM +0100, Sumit Bose wrote:
> On Wed, Jan 25, 2017 at 04:31:16PM +0100, Ralph Böhme wrote:
> > On Wed, Jan 25, 2017 at 04:36:25PM +0200, Alexander Bokovoy wrote:
> > > On ti, 24 tammi 2017, Volker Lendecke wrote:
> > > > On Tue, Jan 24, 2017 at 10:05:23PM +0200, Alexander Bokovoy wrote:
> > > > > > if your corporate strategy mandates sssd.
> > > > > For sssd integration, one can install sssd-winbind-idmap package and use
> > > > >  idmap config DOMAIN : backend = sss
> > > > > 
> > > > > This should be available in RHEL 7.3 and Fedora 25 and their
> > > > > derivatives.
> > > > 
> > > > Is the source code of that module freely available?
> > > Yes, it is part of sssd source:
> > > https://git.fedorahosted.org/cgit/sssd.git/tree/src/lib/winbind_idmap_sss
> > 
> > am I missing something? Why hasn't this been upstreamed?
> 
> I assume you mean Samba upstream. Please see the discussion on this list
> in 2014 in the '[Review Request] libwbclient-sssd' thread
> (https://lists.samba.org/archive/samba-technical/2014-May/099676.html).

thanks for the pointer!

> Since the sss idmap plugin requires that SSSD is running I think the
> same arguments apply here as well.

hm... that was a borged libwbclient, this is just another idmap backend with an
external dependency. :)

This looks like it would be very useful and just needs some waf configure and
build magic to be integrated.

Cheerio!
-slow



More information about the samba-technical mailing list