net getdomainsid SID for local machine HOST is: S-1-5-21-2390795950-2727105968-4008069955 SID for domain EXAMPLE is: S-1-5-21-2390795950-2727105968-4008069955
I compared my smb.conf with yours. I have "ldap suffix" before "ldap group suffix". I switched that but result still the same. ldapsearch -LLLY external -H ldapi:/// cn=admin dn 2>/dev/null dn: cn=admin,dc=example,dc=sk tdbdump /var/lib/samba/secrets.tdb - looks ok ( the password too ) ldapsearch -LLLY external -H ldapi:/// "(&(objectclass=sambaGroupMapping)(|(cn=users)(displayname=users)(uid=users)))" 2>/dev/null dn: sambaSID=S-1-5-32-545,ou=Groups,dc=example,dc=sk objectClass: sambaSidEntry objectClass: sambaGroupMapping sambaSID: S-1-5-32-545 sambaGroupType: 4 displayName: Users gidNumber: 10000 sambaSIDList: S-1-5-21-2390795950-2727105968-4008069955-513 ldapsearch -xLLL "(&(objectclass=sambaGroupMapping)(|(cn=users)(displayname=users)(uid=users)))" dn dn: sambaSID=S-1-5-32-545,ou=Groups,dc=example,dc=sk I do not see anything bad, I do not have installed windbindd.... On Tue, Nov 27, 2012 at 2:46 PM, Harry Jede <walk2...@arcor.de> wrote: > (displayname=users)(uid=users)))" dn > -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba