>       I don't think this is correct.  The biggest danger I see is that the
> e-smith manager would (try to) create a regular user account with the
> same name as a machine account, and only be able to partially create
> that account.  

I stand to be corrected, but machine accounts registered in the unix and
samba password databases are appended with a $ at the end of the machine name.
This design feature of samba was created to avoid the situation you 
describe.  In fact, in my samba network, my login name is greg and my workstation's 
netbios name is greg.  Both exist in the appropriate username databases without
 issue because my machine name is listed as greg$ (not greg).

Further, I think that integrating the Samba machine account process with "e-smith 
way of doing things" is only asking for further development to SME in the future.  
In the near future, Samba will likely have the ability to remove machine accounts when
a machine leaves the domain, thus creating a "hole" in the SME user account structure.

Regards,

Greg J. Zartman






--
Please report bugs to [EMAIL PROTECTED]
Please mail [EMAIL PROTECTED] (only) to discuss security issues
Support for registered customers and partners to [EMAIL PROTECTED]
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
Archives by mail and http://www.mail-archive.com/devinfo%40lists.e-smith.org

Reply via email to