Continuing the saga: Groups are not migrated by the ldap_nua backend, even if I create a posixGroup entry. After a bit of prodding, I found the latter was because Samba had set up group mappings in group_mapping.tdb, which my manually-created LDAP groups didn't agree with. Removing group_mapping.tdb fixed /that/ problem - i.e. accounts have their group information properly updated - but the basic problem, that groups are not migrated - still exists. And it appears that smbgroupedit is not capable of creating a new group in the same way that smbpasswd is capable of creating a new user.
I'm copying this to samba-technical, since I believe it's an implementation detail at this point. Cheers, Waider. -- [EMAIL PROTECTED] / Yes, it /is/ very personal of me. Some people just don't know which side of the good/evil thing to side with, despite the obvious "fun now, pay later" advantages of the evil side for those of us who need instant gratification.
