ok, one step further:

        idmap backend = idmap_rid:DOMA=10000-20000,TRUSTDOMB=20001-30000
        idmap uid = 10000-30000
        idmap gid = 10000-30000
        winbind enum users = no
        winbind enum groups = no
        template shell = /bin/bash
        allow trusted domains = no
        winbind trusted domains only =no
        winbind use default domain = yes

id user (from DOMA) gives a UIDNumber (according to idmap range).

id TRUSTDOMB\user gives
[  978]: sid to uid S-1-5-21-3912345646-894196617-3681078760-4070
rid_idmap_get_id_from_sid: no suitable range available for sid: S-1-5-21-3912345646-894196617-3681078760-4070

???

i think the compile time option -DIdmap_rid_support_trusted_domains is still missing, but how to find this out or how to enable it?

thx!


Michael Gasch wrote:
hi,

i have a question about winbind, idmap_rid and trusted domains. at sambaxp jerry said it's possible to have idmap_rid working with trusted domains. this is what we would like to have here.

smbd -b doesn't show this compile option on 3.0.14a rpm (SuSE). may be this is normal, but how do i ensure that this option is in my binary w/ testing too much :) or how can i compile it myself? will this work only on samba >3.0.14a or with all samba versions that are shipped with idmap_rid support?

thx for your help in advance!
cheerz



--
Michael Gasch
Max Planck Institute for Evolutionary Anthropology
Department of Human Evolution (IT)
Deutscher Platz 6
D-04103 Leipzig
Germany

Phone: 49 (0)341 - 3550 137
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Reply via email to