> > Hope this helps someone, it cost me enough pain before it worked properly
> >  for me.
> Oh yes - regular (existing or new) Posix group users can be anywhere in
> your DSA, 

I think you mean "anywhere in your Dit";  "anywhere in your DSA" doesn't
make much sense,

> in any group (though it makes sense to put computer trusts under
> ou=smb).

I think you mean "in any container".

And you're wrong, they need to be below the search base used by NSS for
the appropriate object type - groups, person, etc...  You can only put
them anywhere if you are using the root of the Dit as your search base
which is generally inadvisable for a number of reasons.

> Simply run smbpasswd or pdbedit (can be done from a script) on each one to
> add them to the domain. Personally I don't use the IDEALX scripts, I write
> my own awk and shell scripts.

Same, we've written .NET (Mono) 'scripts' for doing this.

Attachment: signature.asc
Description: This is a digitally signed message part

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Reply via email to