Ralf Hornik Mailings wrote:
Lukas Haase <[email protected]> wrote:
Is this necessary? Does it cause any problems?

Only the samba DC must be able to access the machine objects. So if you plan to reduce the scope on your PDC, machine autentication, or joining a machine to domain will allways fail.

On client side I can't see problems so far...

Hi,

Thanks for your reply.

Actually this is exactly whats the problem: On the PDC I want NOT to have the external users in the system!

Is there any good solution for that?

It would be great if libnss-ldap would support users from different trees (than I could take ou=int,ou=users AND ou=machines) but I guess this is not possible...

Regards,
Luke

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Reply via email to