[Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-26 Thread Andreas Ladanyi
Hi Doug, i read your mail intently and would thank you for your detailed illustration. ;-) I would change the parameter you suggest and would do some more tests to verify for my comprehension. Bye, Andy Doug VanLeuven schrieb: Andreas Ladanyi wrote: There is one UNIX attribute tab and

Re: [Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-25 Thread Doug VanLeuven
Andreas Ladanyi wrote: There is one UNIX attribute tab and one Members Of tab. During some tests we discover the following facts = In UNIX attribute tab: winbind is only interested in the UID field - in ldap tree the

Re: [Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-24 Thread Doug VanLeuven
Andreas Ladanyi wrote: Hay Jerry, Gerald (Jerry) Carter schrieb: Andreas Ladanyi wrote: Ok ! Could it be true this behavior is different between security=domain and security=ads ? Because we had to put the user to the group: - first on windows side in ActiveFirectory - second on unix site

[Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-24 Thread Andreas Ladanyi
There is one UNIX attribute tab and one Members Of tab. During some tests we discover the following facts = In UNIX attribute tab: winbind is only interested in the UID field - in ldap tree the attribute uidnumber. If you're

[Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-23 Thread Andreas Ladanyi
Hay Jerry, Gerald (Jerry) Carter schrieb: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Ladanyi wrote: Ok ! Could it be true this behavior is different between security=domain and security=ads ? Because we had to put the user to the group: - first on windows side in ActiveFirectory

Re: [Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-21 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Ladanyi wrote: Ok ! Could it be true this behavior is different between security=domain and security=ads ? Because we had to put the user to the group: - first on windows side in ActiveFirectory - second on unix site in AD in the tab

[Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-20 Thread Andreas Ladanyi
Hi Jerry, Gerald (Jerry) Carter schrieb: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Ladanyi wrote: Hi, after deleting winbindd_idmap and winbindd_cache.tdb files: For security =domain AND security=ADS ! wbinfo -u /-g /-t are ok ! getent passwd is ok. getent group shows

Re: [Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-20 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Ladanyi wrote: Winbind honors the Windows group membership and not necessarily msSFU30PosixMemberOf attributes. So it should be enough if you give the Windows group a GID in tab UNIX attribute in Active Directory and you have to do

[Samba] Re: ldapsearch and getent passd/group with nss winbind differs

2008-08-20 Thread Andreas Ladanyi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Ladanyi wrote: Winbind honors the Windows group membership and not necessarily msSFU30PosixMemberOf attributes. So it should be enough if you give the Windows group a GID in tab UNIX attribute in Active Directory and you have to do