Without idmap line, it work too. [global]
workgroup = DDCS security = ADS realm = DDCS.LOCAL encrypt passwords = yes # idmap config *:backend = tdb # idmap config *:range = 70001-80000 # idmap config DDCS:backend = ad # idmap config DDCS:schema_mode = rfc2307 # idmap config DDCS:range = 500-40000 winbind nss info = rfc2307 winbind trusted domains only = no winbind use default domain = yes winbind enum users = yes winbind enum groups = yes What is the really role of idmap's line ? I have of to miss something -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
