On 05/12/2022 15:01, lejeczek via FreeIPA-users wrote:
Hi Gents.

I have a user with UID of 57500500 and Samba's clients would fail with: NT_STATUS_NO_IMPERSONATION_TOKEN while trying to connect/authenticate. There was not idrange in the domain for that ID )so I created one:
...
  Range name: CCN.PRIVATE_id_range
  First Posix ID of the range: 57400000
  Number of IDs in the range: 9999
  First RID of the corresponding RID range: 57400000
  First RID of the secondary RID range: 57409999
  Range type: local domain range

and
-> $ ipa-replica-manage dnarange-show
drunk.in.ccn: 57400000-57409999
sucker.in.ccn: 1600700501-160079999

but I still cannot samba-connect to the service/server, still fails with the same error. Would you know what is wrong and/or what I'm missing - all thoughts share are much appreciated.
many thanks, L.

Perhaps I was wrong to assume that it had to do with 'idranges'?
I did assume that because other users when are created without '--uid' do connect to Samba services perfectly fine.
many thanks, L.
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to