On 1 March 2018 at 18:49, Rowland Penny <rpenny@xxxxxxxxx> wrote:

> > idmap range not specified for domain '*'
> > ERROR: Invalid idmap range for domain *!
> >
> You haven't set the 'idmap config' lines correctly, which may mean you
> are using sssd instead. If this is the case, then you are asking in the
> wrong place, you need to ask on the sssd-users mailing list.

After reading a lot about idmap conf and idmap backends, I'm thinking that
what I've been doing is not expressible with idmap.

What I need is what is described, much better than I did, here:


That is:

Samba will authenticate against AD, and then utilize the normal 'getent'
system calls to gather the uid/gid numbers, and those will come from
OpenLDAP, and/or the local system files as configured within the
nsswitch.conf file.

Is this type of setup still possible?

