Dear Sumit,

thank you for your quick reply and the good hints. 

Access works now as expected. The reason of the failure was one wrong 
libwbclient link. Admins have to really be carefully, when switching to sssd's 
libwbclient.so.

In parallel, I also switched the member server to Samba's winbind to compare 
the outputs, as even up to level 10 there was no useful information in the smbd 
logs. Interestingly the output of smbcacl is now (with winbind):
REVISION:1
CONTROL:SR|PD|SI|DI|DP
OWNER:Unix User\root
GROUP:Unix Group\root
ACL:SAMDOM\Domain Admins:ALLOWED/OI|CI/FULL
ACL:SAMDOM\Domain Users:ALLOWED/OI|CI/READ
ACL:SAMDOM\Department:ALLOWED/OI|CI/CHANGE

smbcacl seems to require winbind to translate SIDs into uids/guids.
On the other hand getent group domain\ admins now prints: 
domain [email protected]:*:512. 
I. e. on the linux side the group member information gets lost when using 
winbind.

From a long samba list discussion I have got the impression, that it's more a 
philosophy question, if to use sssd or winbind on a domain member server. Do 
you still agree? Or what is your recommendation especially, when taking your 
long term statement above into account.

Best regards

Thomas
_______________________________________________
sssd-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to