[Samba] Access and group issues on domain member server (PDC is Samba as well)

2012-08-01 Thread Philipp Felix Hoefler
Hi List, I created a domain member server in my samba domain. I start to realize that there are some issues when colleagues could not access some folders in the their shares. After searching for a solution I found that on that member server I have no samba groups available. First of all my

Re: [Samba] Access and group issues on domain member server (PDC is Samba as well)

2012-08-01 Thread Daniel Müller
Hi there, try : id youruser.ldap on the memberserver, ex.: [root@tuepdc ~]# id tester uid=1010(tester) gid=513(Domain Users) Gruppen=513(Domain Users),2154(orbis),34709(Dienstplan),61092(HS3),47140(DIFAEM),17162(agfa),29

Re: [Samba] Access and group issues on domain member server (PDC is Samba as well)

2012-08-01 Thread Philipp Felix Hoefler
Hi Daniel, thank you for you response. [root@srvfile1 home]# id phoefler uid=1663(phoefler) gid=1105(VISIONS) groups=1105(VISIONS),512(Domain Admins),513(Domain Users),1103(IT),1069(Marketing),1079(TimeSheetReports) This is working correctly. Also all other linux - LDAP stuff is working

Re: [Samba] Access and group issues on domain member server (PDC is Samba as well)

2012-08-01 Thread Daniel Müller
Did you miss this in your members smb.conf: passdb backend = ldapsam:ldap://192.168.249.7/ So your ldapclient is working but Samba does not now where to auth? Your config on memberserver: Server role: ROLE_DOMAIN_MEMBER Press enter to see a dump of your service definitions [global] unix

Re: [Samba] Access and group issues on domain member server (PDC is Samba as well)

2012-08-01 Thread Gaiseric Vandal
I think there are two components- 1st I think the domain member does need to run winbind to retrieve windows users and groups from the DC. 2nd, the domain member needs to have idmap configured correctly to make sure that the windows users are properly mapped to the local unix users, so that

Re: [Samba] Access and group issues on domain member server (PDC is Samba as well)

2012-08-01 Thread Philipp Felix Hoefler
Hi Daniel! Oh my god, how embarrassing ;-) This was it! Resolved all problems. Vielen Dank! Liebe Grüsse nach Tübingen, philipp On 8/1/12 1:42 PM, Daniel Müller wrote: Did you miss this in your members smb.conf: passdb backend = ldapsam:ldap://192.168.249.7/ So your ldapclient is working but