Web lists-archives.com

Re: [Samba] getent passwd no domainusers




On Mon, 8 Oct 2018 15:56:59 +0200
basti.mueller31@xxxxxx wrote:

> Hi Rowland,
> 
> yesterday night I found out the problem.. The migrated samba server
> was like 10 years old. There are 2 problems with the id-range of my
> users/groups.
> 
> The first id of a domain group is "512" (EXAMPLE\domain admins)
> and the last one is: "3000040" (EXAMPLE\dnsupdateproxy)

That doesn't look like a gidNumber, it looks like an xidNumber
if it is an xidNumber, then I am surprised setting the upper range to
'4000000' works, xidNumber's are NOT used on a Unix domain member.

> 
> I didn't add them by myself..the migration-process created the
> dnsupdateproxy for example.
> 
> so I just set the range on my client to:
> idmap config EXAMPLE : backend = ad
> idmap config EXAMPLE : schema_mode = rfc2307
> idmap config EXAMPLE : range = 0-4000000
> 
> now it works.
> 

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba