Thanks Rowland,

> No, that is how the 'rid' backend works.

Would love to know what my misconceptions are. But yeah, this is not a
tutorial group :-)

> > I'm thinking perhaps I should implement an idmap_script backend that
> > does something similar to idmap_nis.sh
> Well, you could, but I feel you are missing the whole point behind AD,

I get the central management thing. Point is we are centrally managing
users. It's done by the identity management system. The IDM provisions both
LDAP and AD (and other targets). Passwords and many other attributes are
also managed centrally.

To get new attributes in AD would require probably 6 months of change
requests, committees, contractors, stuff-ups, and all the rest that goes
with working in big organization :-(

Point is the samba update from 4.6.x to 4.7.x broke my samba shares and the
problem seems to be in how idmap is handled now.

My fault for not doing enough testing, but this is where I am now.

Rolling back samba is difficult also. Means I would have to install outside
the package management system, I don't want go back to those days.

Thanks for your help, I do appreciate it.
Norman Gaywood, Computer Systems Officer
School of Science and Technology
University of New England
Armidale NSW 2351, Australia

ngaywood@xxxxxxxxxx   http://turing.une.edu.au/~ngaywood
Phone: +61 (0)2 6773 2412  Mobile: +61 (0)4 7862 0062

Please avoid sending me Word or Power Point attachments.
See http://www.gnu.org/philosophy/no-word-attachments.html
