Hi there, I have just discovered that my winbind installation (3.0 alpha 24 w/ACLs, RH 8.0, connected to a Windows 2000 ADS domain) seems to be no longer mapping groups correctly. Executing the "groups" command for any particular domain user fails, complaining that it can't get the group name for various winbind-ranged gids. Doing an ls of a directory created from Windows via samba works fine, however, listing the user/group names correctly. Here is a somewhat worrying excerpt from log.winbindd: ---------- snip --------- [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Server Operators !? [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Account Operators !? [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Print Operators !? [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Pre-Windows 2000 Compatible Access !? [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Users !? [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Administrators !? [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Guests !? [2003/06/11 15:50:00, 1] nsswitch/winbindd_sid.c:winbindd_sid_to_uid(142) Could not get uid for sid S-1-5-21-1708537768-2139871995-725345543-1151 [2003/06/11 15:50:45, 1] nsswitch/winbindd_util.c:rescan_trusted_domains(168) scanning trusted domain list [2003/06/11 15:55:53, 1] nsswitch/winbindd_util.c:rescan_trusted_domains(168) scanning trusted domain list ---------- snip --------- In all other respects winbind & samba seem to be operating correctly. Any ideas? Cheers, Paul --------------------------------------------------------- Paul Eggleton Ph: +64-9-4154790 Software Developer Fax: +64-9-4154791 CJN Technologies Ltd. DDI: +64-9-4154795 http://www.cjntech.co.nz Email: paule@cjntech.co.nz ---------------------------------------------------------
Paul, Suggest you try this with samba-3.0.0-beta1. If you still have a problem please let us know. - John T. On Wed, 11 Jun 2003, Paul Eggleton wrote:> Hi there, > > I have just discovered that my winbind installation (3.0 alpha 24 > w/ACLs, RH 8.0, connected to a Windows 2000 ADS domain) seems to be no > longer mapping groups correctly. Executing the "groups" command for any > particular domain user fails, complaining that it can't get the group > name for various winbind-ranged gids. Doing an ls of a directory created > from Windows via samba works fine, however, listing the user/group names > correctly. > > Here is a somewhat worrying excerpt from log.winbindd: > ---------- snip --------- > [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) > No rid for Server Operators !? > [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) > No rid for Account Operators !? > [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) > No rid for Print Operators !? > [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) > No rid for Pre-Windows 2000 Compatible Access !? > [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) > No rid for Users !? > [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) > No rid for Administrators !? > [2003/06/11 15:48:29, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) > No rid for Guests !? > [2003/06/11 15:50:00, 1] > nsswitch/winbindd_sid.c:winbindd_sid_to_uid(142) > Could not get uid for sid > S-1-5-21-1708537768-2139871995-725345543-1151 > [2003/06/11 15:50:45, 1] > nsswitch/winbindd_util.c:rescan_trusted_domains(168) > scanning trusted domain list > [2003/06/11 15:55:53, 1] > nsswitch/winbindd_util.c:rescan_trusted_domains(168) > scanning trusted domain list > ---------- snip --------- > > In all other respects winbind & samba seem to be operating correctly. > Any ideas?-- John H Terpstra Email: jht@samba.org