[Samba] Questions about SIDs and sambaDomains

2007-10-26 Thread Hadmut Danisch
Hi, just two questions which I could not find precise answers for in web and books: When I have n samba servers, sharing the same LDAP tree, is that correct that I have n+1 sambaDomain entries in LDAP, one for each host and another one for the workgroup? Wouldn't a single doman entry be suffi

[Samba] Samba+LDAP: Groups and Groupmappings?

2007-08-17 Thread Hadmut Danisch
Hi, just a question about the representation of Windows Domain groups in LDAP when using the ldapsam backend: What exactly is required to have a Windows Domain group properly configured? Am I correct that there is only a single LDAP object of - objectClasses sambaGroupMapping and posixGroup,

[Samba] Migrating NT4->Samba3: Found bogus group member...

2007-08-16 Thread Hadmut Danisch
Hi, today I tried to migrate an old NT4 PDC to Samba 3 as described in http://samba.org/samba/docs/man/Samba-HOWTO-Collection/NT4Migration.html but with the Samba databases on LDAP: Whenever I tried that net rpc vampire -S NT4PDC -U administrator%passwd I received error messages that th

Re: [Samba] Re: Questions about samba+LDAP

2007-08-08 Thread Hadmut Danisch
Hi Matt, On Wed, Aug 08, 2007 at 06:20:42PM +, Matt Anderson wrote: > passdb backend = "ldapsam:ldaps://192.168.2.2 ldaps://192.168.2.3" Well, I had already tried this (replication first, master second) but got an error message about missing write access. The problem seems to be that samba

[Samba] Questions about samba+LDAP

2007-08-08 Thread Hadmut Danisch
Hi, just three simple questions about samba+LDAP: Samba allows to configure several LDAP suffixes, ldap group suffix ldap idmap suffix ldap machine suffix ldap user suffix and the general ldap base with ldap suffix. But is there a way to configure a suffix for the sambaDomain objects? When I