On Mon, Jun 12, 2006 at 07:36:49PM -0600, Diego Rivera wrote:
> Thanks for the quick answer anyway.  So, according to AD ACL's, it's 
> possible that a machine in a domain which needs to check group access 
> (i.e. a samba box) may not get accurate information about whether a user 
> is a member of a group? Or just that the ACL's may forbid the 
> enumeration of group members for particular groups?

The latter. The operation that will always work is to return
the groups a user is in when logging in as that user.

Volker

Attachment: pgpAKWOhqJkFC.pgp
Description: PGP signature

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Reply via email to