Web lists-archives.com

Re: [Samba] wbinfo -i returns the same id for all users, authentication doesn't seem to go through winbind at all




On Sat, 18 Feb 2017 18:13:39 +0100
Emmanuel Florac <eflorac@xxxxxxxxxxxxxx> wrote:

> 
> Both, alas. I'll retry by entering everything as you proposed instead
> of editing the existing file.

Please do, it should work

> Here:
> https://wiki.samba.org/index.php/FAQ#I_have_set_up_a_domain_member_using_the_idmap_ad_backend.2C_but_getent_passwd_and_getent_group_do_not_show_users_or_groups

Nope, that isn't obsolete, I should know, I wrote it ;-)


> > But only if your users have a uidNumber attribute and Domain
> > Users has a gidNumber attribute.
> > 
> 
> You mean from the ADC? The ADC is W2K8R2, not Samba.
> 

Just because your DC is a windows one doesn't mean you don't have to
add the uidNumber & gidNumber attributes if you use the windbind 'ad'
backend, but if you use the smb.conf I suggested, you will be using the
'rid' backend and this doesn't need anything adding to AD. I 

Can you check the join 'net ads testjoin' it should return 'Join is OK'

does the domain member use the DC as its nameserver

What is in /etc/krb5.conf

What does 'pam-auth-update' show as authentication methods

Rowland

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba