question: where is the "convert" script/program you mention? can't seem to find it anywhere...

Thanks.

-Jeff

boka wrote:

Jeff Davis wrote:

If you arrive at a solution, please let me know...


i did not have free time to analyze why it start working, but i made it :)

First of all, i have converted (again) old ldap db:

ldapsearch -h .... > old.ldiff

net getlocalsid DOMAIN

convert .... --output new.ldif

Then add it to ldap and add new indexes (taken from samba-ldap.howto).

ldapadd -h localhost -f new.ldif -D ....

add it to slapd.conf to Your DB definition:

index           cn,sn,uid,displayName           pres,sub,eq
index           uidNumber,gidNumber             eq
index           sambaSID                        eq
index           sambaPrimaryGroupSID            eq
index           sambaDomainName                 eq
index           objectClass                     pres,eq
index           default                         sub
index memberUid     eq

slapdindex -f /etc/openldap/slapd.conf

I have compiled samba only with --with-ldap option (without --with-ldapsam). Add proper filters to groups, users, computers in smb.conf:

ldap suffix used to search for user and computer accounts.
ldap user suffix used to store user accounts.
ldap machine suffix used to store Machine Trust Accounts.
ldap group suffix location of posixGroup/sambaGroupMapping entries.
ldap idmap suffix location of sambaIdmapEntry objects.

Right now i cant compare the new ldap db with old (first converted) but i think there was a problem with samaDomain parametr ...

greetz
boka


-- Jefferson K. Davis Technology and Information Systems Manager Standard School District 1200 North Chester Ave Bakersfield, CA 93308 USA 661-392-2110 ext 120

--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba

Reply via email to