Re: [Samba] getent passwd no domainusers

On Mon, 8 Oct 2018 15:56:59 +0200
basti.mueller31@xxxxxx wrote:

> Hi Rowland,
> yesterday night I found out the problem.. The migrated samba server
> was like 10 years old. There are 2 problems with the id-range of my
> users/groups.
> The first id of a domain group is "512" (EXAMPLE\domain admins)
> and the last one is: "3000040" (EXAMPLE\dnsupdateproxy)

That doesn't look like a gidNumber, it looks like an xidNumber
if it is an xidNumber, then I am surprised setting the upper range to
'4000000' works, xidNumber's are NOT used on a Unix domain member.

> I didn't add them by myself..the migration-process created the
> dnsupdateproxy for example.
> so I just set the range on my client to:
> idmap config EXAMPLE : backend = ad
> idmap config EXAMPLE : schema_mode = rfc2307
> idmap config EXAMPLE : range = 0-4000000
> now it works.

