Re: [Samba] Samba 4.8 Config SMB.Conf File

On Fri, 15 Mar 2019 10:34:18 -0400
Tyrus Shivers <tyrus.shivers@xxxxxxxxxxxxxxx> wrote:

> Yes for joining the domain.
> Running testjoin I get: Join is OK.
> The network is separated and does not access the open internet so I
> have to come on another network to email you all :)

OK, What is the DC and where is it ?
Inside the network or outside ?

> getent passwd returns nothing for me.
> id returns no such user.
> Question:
> The original SMB.conf that was on the system when I inherited it
> running 7.3 and Samba 4.4 did not have mydomain lines and just had
> the * and the backend was rid. It worked. You said that was incorrect
> setup.

It was, the '*' domain is meant for the Well Known SID's and anything
outside the listed domains, Whilst it will sort of work, it wont work
correctly. Using 'rid' compounds the error, as you need an allocating

> workgroup = mydomain
> password server = hostname.mydomain.com
> realm = mydomain.com
> security = ads
> idmap config * : range = 10000-19999
> idmap config * : backend = rid
> Why on 4.4 does the above work and not on 4.8?

The main change between 4.4. & 4.8 is that winbind nows needs to be

> Since changing to the tdb backend it shows no such user. If I remove
> those line and go back to the original it will not start. If I add my
> domain and keep the * lines it gives me a user, but the wrong UIDs.
> The ranges do overlap in that case though which I know is not correct.
> Is there something specific that I need to setup with a tdb backend?
> Other configurations that I am missing?

I am wondering if this gives a clue:

password server = hostname.mydomain.com

What is 'hostname.mydomain.com' and where is it ?


