Upgraded to 4.8 - forced to use winbindd - retro how to missing?

On Wed, 28 Nov 2018 16:48:09 -0500
Richard Bollinger <rabollinger@xxxxxxxxx> wrote:

> winbind is running and I fixed the ranges.  testparm seems happy
> now.  Same result.
> Any other suggestions?

Well, 'man idmap_nss' says this:

The idmap_nss plugin provides a means to map Unix users and groups to Windows accounts. 
This provides a simple means of ensuring that the SID for a Unix user named jsmith is reported as the one assigned to DOMAIN\jsmith which is necessary for reporting ACLs on files and printers stored on a Samba member server.

So, from that, it is possible you are hitting the 'supplementary
groups are not found unless the user has logged in' feature.

You may never get this to work as you want.


